Description
The Motors WordPress plugin before 1.4.4 does not properly validate uploaded files for dangerous file types (such as .php) in an AJAX action, allowing an attacker to sign up on a victim's WordPress instance, upload a malicious PHP file and attempt to launch a brute-force attack to discover the uploaded payload.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-43318 | The Motors WordPress plugin before 1.4.4 does not properly validate uploaded files for dangerous file types (such as .php) in an AJAX action, allowing an attacker to sign up on a victim's WordPress instance, upload a malicious PHP file and attempt to launch a brute-force attack to discover the uploaded payload. |
References
History
Tue, 22 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-04-22T14:45:06.597Z
Reserved: 2022-11-14T14:45:02.983Z
Link: CVE-2022-3989
Updated: 2024-08-03T01:27:54.119Z
Status : Modified
Published: 2022-12-12T18:15:12.553
Modified: 2025-04-22T15:16:02.310
Link: CVE-2022-3989
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.
EUVD