Vulnerability detail
Enriched intelligence for a single CVE
Critical
CVE-2025-4322
PUBLISHEDMotors <= 5.6.67 - Unauthenticated Privilege Escalation via Password Update/Account Takeover
- Vendor
- StylemixThemes
- Product
- Motors - Car Dealer, Rental & Listing WordPress theme
- Published
- May 20, 2025
- EPSS
- —
Automate this intelligence with the Pro API
Everything on this page — CVSS, EPSS, exploit status, PoCs, scanner integrations, mentions, tags, and immediate honeypot data — is available programmatically for VM, SOC, and CTI workflows.
Description
The Motors theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.6.67. This is due to the theme not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user passwords, including those of administrators, and leverage that to gain access to their account.
Weaknesses (CWE)
-
Unverified Password Change
CVSS scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation status
No exploitation signals recorded yet.
Scanner integrations
| Scanner | Reference | Detected |
|---|---|---|
| Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-4322.yaml | Jun 01, 2026 |
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Detected by Nuclei