CVE-2025-64374

9.9

StylemixThemes · Motors WordPress theme

The Motors theme for WordPress by StylemixThemes contains an unrestricted file upload vulnerability, allowing authenticated attackers to execute malicious files.

Executive summary

An unrestricted file upload vulnerability in the StylemixThemes Motors WordPress theme allows authenticated attackers to execute arbitrary code, potentially leading to full site compromise.

Vulnerability

This is an unrestricted file upload vulnerability (CWE-434) that allows an authenticated attacker (Low privileges) to upload and execute arbitrary malicious files on the server.

Business impact

An attacker who successfully exploits this vulnerability can achieve remote code execution on the underlying WordPress server. This could lead to total site takeover, data exfiltration, or the injection of malicious content, severely damaging the business's reputation and operational integrity.

Remediation

Immediate Action: Update the Motors WordPress theme to version 5.6.83 or later immediately.

Proactive Monitoring: Scan the WordPress media uploads directory for unexpected file types (e.g., .php, .phtml) and review server access logs for requests to non-media files in the upload path.

Compensating Controls: Use a Web Application Firewall (WAF) to block suspicious file upload attempts and restrict access to administrative interfaces that allow file uploads.

Exploitation status

Public Exploit Available: No.

Analyst recommendation

Plugin and theme vulnerabilities are a common vector for WordPress compromises; it is essential to keep the Motors theme updated to the latest version. Failure to patch this vulnerability leaves the site highly susceptible to complete administrative takeover.

More StylemixThemes CVEs