CVE-2022-3989

The Motors WordPress plugin before 1.4.4 does not properly validate uploaded files for dangerous file types (such as .php) in an AJAX action, allowing an attacker to sign up on a victim's WordPress instance, upload a malicious PHP file and attempt to launch a brute-force attack to discover the uploaded payload.
Configurations

Configuration 1 (hide)

cpe:2.3:a:stylemixthemes:motors_-_car_dealer\,_classifieds_\&_listing:*:*:*:*:*:wordpress:*:*

History

21 Nov 2024, 07:20

Type Values Removed Values Added
Summary
  • (es) El complemento de WordPress Motors anterior a 1.4.4 no valida adecuadamente los archivos cargados para tipos de archivos peligrosos (como .php) en una acción AJAX, lo que permite a un atacante registrarse en la instancia de WordPress de una víctima, cargar un archivo PHP malicioso e intentar iniciar un ataque de fuerza bruta para descubrir el payload cargado.
References () https://wpscan.com/vulnerability/1bd20329-f3a5-466d-81b0-e4ff0ca32091 - Exploit, Third Party Advisory () https://wpscan.com/vulnerability/1bd20329-f3a5-466d-81b0-e4ff0ca32091 - Exploit, Third Party Advisory

Information

Published : 2022-12-12 18:15

Updated : 2025-04-22 15:16


NVD link : CVE-2022-3989

Mitre link : CVE-2022-3989

CVE.ORG link : CVE-2022-3989


JSON object : View

Products Affected

stylemixthemes

  • motors_-_car_dealer\,_classifieds_\&_listing
CWE

No CWE.