CVE-2025-64374
9.9StylemixThemes · Motors WordPress theme
The Motors theme for WordPress by StylemixThemes contains an unrestricted file upload vulnerability, allowing authenticated attackers to execute malicious files.
Executive summary
An unrestricted file upload vulnerability in the StylemixThemes Motors WordPress theme allows authenticated attackers to execute arbitrary code, potentially leading to full site compromise.
Vulnerability
This is an unrestricted file upload vulnerability (CWE-434) that allows an authenticated attacker (Low privileges) to upload and execute arbitrary malicious files on the server.
Business impact
An attacker who successfully exploits this vulnerability can achieve remote code execution on the underlying WordPress server. This could lead to total site takeover, data exfiltration, or the injection of malicious content, severely damaging the business's reputation and operational integrity.
Remediation
Immediate Action: Update the Motors WordPress theme to version 5.6.83 or later immediately.
Proactive Monitoring: Scan the WordPress media uploads directory for unexpected file types (e.g., .php, .phtml) and review server access logs for requests to non-media files in the upload path.
Compensating Controls: Use a Web Application Firewall (WAF) to block suspicious file upload attempts and restrict access to administrative interfaces that allow file uploads.
Exploitation status
Public Exploit Available: No.
Analyst recommendation
Plugin and theme vulnerabilities are a common vector for WordPress compromises; it is essential to keep the Motors theme updated to the latest version. Failure to patch this vulnerability leaves the site highly susceptible to complete administrative takeover.