CVE-2022-3989
Last modified
CVE-2022-3989 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. The Motors WordPress plugin before 1.4.4 does not properly validate uploaded files for dangerous file types (such as .php) in an AJAX action, allowing an attacker to sign up on a victim's WordPress instance, upload a malicious PHP file and attempt to launch a brute-force attack to discover the uploaded payload.. EPSS estimates a 1.05% chance of exploitation in the next 30 days.
Description
The Motors WordPress plugin before 1.4.4 does not properly validate uploaded files for dangerous file types (such as .php) in an AJAX action, allowing an attacker to sign up on a victim's WordPress instance, upload a malicious PHP file and attempt to launch a brute-force attack to discover the uploaded payload.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Stylemixthemes | Motors - Car Dealer\, Classifieds \& Listing | < 1.4.4 |
References
- https://wpscan.com/vulnerability/1bd20329-f3a5-466d-81b0-e4ff0ca32091Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/1bd20329-f3a5-466d-81b0-e4ff0ca32091Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-3989?
How severe is CVE-2022-3989?
How do I fix CVE-2022-3989?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-39884Improper access control vulnerability in IImsService prior t…3.3
- CVE-2022-39885Improper access control vulnerability in BootCompletedReceiv…3.3
- CVE-2022-39886Improper access control vulnerability in IpcRxServiceModeBig…3.3
- CVE-2022-39887Improper access control vulnerability in clearAllGlobalProxy…3.3
- CVE-2022-39888Improper access control vulnerability in retrieveExternalPro…4.3
- CVE-2022-39889Improper access control vulnerability in GalaxyWatch4Plugin …3.3
- CVE-2022-39890Improper Authorization in Samsung Billing prior to version 5…7.5
- CVE-2022-39891Heap overflow vulnerability in parse_pce function in libsavs…7.5
- CVE-2022-39892Improper access control in Samsung Pass prior to version 4.0…9.8
- CVE-2022-39893Sensitive information exposure vulnerability in FmmBaseModel…3.3
- CVE-2022-39894Improper access control vulnerability in ContactListStartAct…3.3
- CVE-2022-39895Improper access control vulnerability in ContactListUtils in…3.3
Are you affected by CVE-2022-3989?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
