CVE-2025-4322Patch

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Motors theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.6.67. This is due to the theme not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user passwords, including those of administrators, and leverage that to gain access to their account.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-620

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-05-06)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-17: 1Mentions · 2026-05-06: 2Patch / Workaround · 2026-05-06: 1Technical Details · 2026-02-17: 1Technical Details · 2026-05-06: 202-1705-06
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-171
Disclosure1
2026-05-062
Patch2
Full discourse3 posts
  • Mr.Rabbit@01ra66it
    Patch

    【CVE-2025-4322 Detail】 NVDは、CVE-2025-4322をWordPressテーマ「Motors」の権限昇格脆弱性として掲載しています。対象は5.6.67以下で、ユーザーの本人性を適切に検証せずにパスワード変更が行われることにより、未認証攻撃者が管理者を含む任意ユーザーのパスワードを変更できる可能性があります。 この脆弱性が危険なのは、WordPress管理者アカウントを奪われると、Webサイト全体の改ざんや不審プラグイン設置に直結する点です。企業サイトでは、Web改ざんだけでなく、フィッシングページ設置、SEOスパム、顧客情報窃取、メール悪用にもつながり得ます。 防御側は、Motorsテーマの利用有無とバージョン、管理者ユーザー追加、パスワード変更履歴、テーマファイル改ざんを確認すべきです。WAF/IPSがある場合も、根本対策はテーマ更新と侵害確認である点を忘れてはいけません。 #CVE20254322 #WordPress #MotorsTheme #Web改ざん #脆弱性対応 #CMS https://nvd.nist.gov/vuln/detail/CVE-2025-4322

    Post summary

    The announcement explains CVE-2025-4322, a privilege‑escalation flaw in WordPress Motors theme (≤5.6.67) that allows unauthenticated attackers to change any user’s password, and urges theme users to update to mitigate the risk.

    000011.3K
    3.7K followersView on X
  • Mr.Rabbit@01ra66it
    Patch

    【DPIルール他更新情報:26-019(2026年5月5日)】 Trend Microは、2026年5月5日のDPIルール更新として、WordPressテーマ「Motors」の権限昇格脆弱性 CVE-2025-4322 に対応するWebサーバHTTPS向けルールを掲載しました。脆弱性自体は過去に公表済みですが、防御製品側の検知・防御ルール更新として注目すべき内容です。 CVE-2025-4322は、WordPressの管理者を含むアカウント乗っ取りにつながり得る脆弱性です。日本国内でもWordPressは企業サイト、採用サイト、自治体関連サイト、医療・教育機関の委託運用サイトで広く使われており、テーマの脆弱性は見落とされがちです。 防御側は、WAF/IPSのルール更新だけで安心せず、Motorsテーマの利用有無、バージョン、管理者ユーザー、パスワード変更履歴、不審プラグイン、`wp-content/uploads` 配下のPHPを確認すべきです。Web改ざんやフィッシング設置の初期兆候もあわせて見る必要があります。 #WordPress #CVE20254322 #TrendMicro #WAF #Webセキュリティ #SOC https://www.trendmicro.com/vinfo/jp/threat-encyclopedia/vulnerability/9214/26019-may-5-2026

    Post summary

    Trend Micro released a DPI rule update to detect and mitigate the WordPress theme "Motors" privilege‑escalation flaw CVE-2025-4322, noting additional manual checks for affected sites.

    000001.3K
    3.7K followersView on X
  • y1 uda@abyo software@y1uda
    Disclosure

    CVE-2025-4322: Motorsテーマのパスワードリセット権限昇格 [CVSS 9.8 Critical] | Nyambush セキュリティブログ https://nyambush.app/blog/wp-motors-privesc #Nyambush #WordPress #WPSec #セキュリティ

    Post summary

    A blog post discloses a critical privilege‑escalation vulnerability (CVE‑2025‑4322) in the Motors WordPress theme, citing a CVSS score of 9.8.

    0000065
    175 followersView on X

Explore more