• News/
  • https://www.bleepingcomputer.com/news/security/wordpress-motors-theme-flaw-mass-exploited-to-hijack-admin-accounts/

WordPress Motors theme flaw mass-exploited to hijack admin accounts

BleepingComputer
·
Bill Toulas
·
Published Jun 21, 2025
·
Updated

Hackers are exploiting a critical privilege escalation vulnerability in the WordPress theme "Motors" to hijack administrator accounts and gain complete control of a targeted site. The malicious activity was spotted by Wordfence, which had warned last month about the severity of the flaw, tracked under CVE-2025-4322, urging users to upgrade immediately. Motors, developed by StylemixThemes, is a WordPress theme popular among automotive-related websites. It has 22,460 sales on the EnvatoMarket and is backed by an active community of users. The privilege escalation vulnerability was discovered on May 2, 2025, and first reported by Wordfence on May 19, impacting all versions before and including 5.6.67. The flaw arises from an improper user identity validation during password updating, allowing unauthenticated attackers to change administrator passwords at will. StylemixThemes released Motors version 5.6.68, which addresses CVE-2025-4322, on May 14, 2025, but many users failed to apply the update by Wordfence's disclosure and got exposed to elevated exploitation risk. As Wordfence confirms in a new writeup, the attacks began on May 20, only a day after they publicly disclosed the details. Wide-scale attacks were observed by June 7, 2025, with Wordfence reporting blocking 23,100 attempts against its customers. The vulnerability is in the Motors theme's "Login Register" widget, including password recovery functionality. The attacker first locates the URL where this widget is placed...

Read full article

Affected Software

1 affected component
StylemixThemes Motors=5.6.67
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical vulnerability in the WordPress 'Motors' theme that is being exploited to hijack admin accounts.

2

What security implications are discussed in the article?

The article highlights the risk of unauthorized access to WordPress sites due to a privilege escalation vulnerability.

3

What product is affected by the exploit?

The affected product is the StylemixThemes Motors theme version 5.6.67.

4

Who discovered the vulnerability being exploited?

The vulnerability was spotted by Wordfence, a cybersecurity firm focusing on WordPress security.

5

What actions should users take in response to this issue?

Users of the Motors theme are advised to update to the latest version immediately to mitigate the risk.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203