First published: Mon Dec 12 2022(Updated: )
The Motors WordPress plugin before 1.4.4 does not properly validate uploaded files for dangerous file types (such as .php) in an AJAX action, allowing an attacker to sign up on a victim's WordPress instance, upload a malicious PHP file and attempt to launch a brute-force attack to discover the uploaded payload.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Stylemixthemes Motors - Car Dealer\, Classifieds \& Listing | <1.4.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-3989 is high with a CVSS score of 8.8.
CVE-2022-3989 affects the Motors WordPress plugin before version 1.4.4.
The issue in CVE-2022-3989 is that the Motors WordPress plugin does not properly validate uploaded files for dangerous file types, allowing an attacker to upload a malicious PHP file.
An attacker can sign up on a victim's WordPress instance, upload a malicious PHP file, and attempt to launch a brute-force attack to discover the uploaded file's path.
To fix CVE-2022-3989, update the Motors WordPress plugin to version 1.4.4 or later.