A critical vulnerability has been identified in the “Motors” theme for WordPress, affecting versions 5.6.67 and earlier. This flaw allows an attacker, without needing access or any type of authorization, to change the password of any user on an affected website, including administrators. Successful exploitation of this vulnerability could grant the attacker full control over the site, allowing them to modify content, steal sensitive information, or install malicious software.
| Product | motors |
| Date | 2025-05-29 17:15:24 |
| Information |
|
Technical Summary
The WordPress Motors theme, up to and including version 5.6.67, is vulnerable to an Unauthenticated Privilege Escalation (CVE-2025-4322), classified as CWE-620 (Unverified Password Change). The vulnerability resides in the front-end password update mechanism, accessible via endpoints such as /loginregister/, /login/, or /register/.
An unauthenticated attacker can craft a specific HTTP POST request directed at one of these endpoints. The request must include the user_id of the target account, a new password value for the stm_new_password parameter, and an hash_check parameter. The theme code does not correctly validate either the hash_check parameter or the identity and authorization of the user making the request. This allows the attacker to provide an arbitrary or easily bypassable value for hash_check (e.g., %C0).
Because there is a lack of robust authentication, nonce validation, or ownership verification linked to the user_id before processing the password change, the system blindly updates the password for the specified user_id. This allows an attacker to reset the password of any user, including administrators, thereby gaining unauthorized administrative access and full control over the WordPress installation. The attack does not require prior authentication and can be difficult to detect without active log monitoring.
Recommendations
- Update Immediately: The most important step is to update the Motors theme to the correct and most recent version (higher than 5.6.67) as soon as possible. The vendor has released a patch that resolves the issue.
- Virtual Patching (WAF): If immediate updating is not possible, implement Web Application Firewall (WAF) rules to block or monitor malicious POST requests to the vulnerable endpoints (e.g.,
/loginregister/). Specifically, rules should target requests that include theuser_idandstm_new_passwordparameters without proper session authentication or originating from untrusted sources.
Protect your organisation with Threat Intelligence and Digital Risk Protection.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
