The Motors WordPress plugin before 1.4.4 does not properly validate uploaded files for dangerous file types (such as .php) in an AJAX action, allowing an attacker to sign up on a victim's WordPress instance, upload a malicious PHP file and attempt to launch a brute-force attack to discover the uploaded payload.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2022-12-12T17:54:58.545Z

Updated: 2024-08-03T01:27:54.119Z

Reserved: 2022-11-14T14:45:02.983Z

Link: CVE-2022-3989

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-12-12T18:15:12.553

Modified: 2023-11-07T03:52:04.693

Link: CVE-2022-3989

cve-icon Redhat

No data.