CVE-2022-3989: Motors - Car Dealer, Classifieds & Listing < 1.4.4 - Arbitrary File Upload
The Motors WordPress plugin before 1.4.4 does not properly validate uploaded files for dangerous file types (such as .php) in an AJAX action, allowing an attacker to sign up on a victim's WordPress instance, upload a malicious PHP file and attempt to launch a brute-force attack to discover the uploaded payload.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-3989?
The severity of CVE-2022-3989 is high with a CVSS score of 8.8.
How does CVE-2022-3989 affect the Motors WordPress plugin?
CVE-2022-3989 affects the Motors WordPress plugin before version 1.4.4.
What is the issue in CVE-2022-3989?
The issue in CVE-2022-3989 is that the Motors WordPress plugin does not properly validate uploaded files for dangerous file types, allowing an attacker to upload a malicious PHP file.
What can an attacker do with CVE-2022-3989?
An attacker can sign up on a victim's WordPress instance, upload a malicious PHP file, and attempt to launch a brute-force attack to discover the uploaded file's path.
How can I fix CVE-2022-3989?
To fix CVE-2022-3989, update the Motors WordPress plugin to version 1.4.4 or later.