
Cloud Vulnerability DB
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
The Motors theme for WordPress contains a critical vulnerability (CVE-2025-4322) affecting all versions up to and including 5.6.67. The vulnerability was discovered in May 2025 and reported through Wordfence's bug bounty program by a researcher known as 'Foxyyy'. The Motors theme, developed by StylemixThemes, is a premium WordPress theme specifically designed for car dealerships, rental services, and automotive businesses, with over 22,000 installations currently affected (Wiz Report, Help Net Security).
CVE-2025-4322 is classified as an unauthenticated privilege escalation vulnerability (CWE-620: Unverified Password Change). The vulnerability has received a CVSS v3.1 base score of 9.8 (CRITICAL) with a vector string of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The security flaw stems from improper validation of user identity during password update operations, allowing unauthenticated attackers to modify passwords for any user account, including administrators (NVD, Wiz Report).
The vulnerability enables attackers to gain full administrative access to affected WordPress sites. Once compromised, attackers can inject malicious scripts, steal user data, modify download links to serve malware, redirect visitors to malicious websites, install backdoors, and access sensitive information stored in the underlying database (Help Net Security).
Site administrators using the Motors theme are strongly advised to upgrade to version 5.6.68, which contains the patch released on May 14, 2025. Additionally, administrators should review their logs for unauthorized password changes and suspicious access patterns. If compromise is suspected, sites should be temporarily disabled, all passwords reset, unauthorized accounts removed, and WordPress core files verified for integrity (Help Net Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
A comprehensive threat intelligence database of cloud security incidents, actors, tools and techniques
A step-by-step framework for modeling and improving SaaS and PaaS tenant isolation
Get a personalized demo
“Best User Experience I have ever seen, provides full visibility to cloud workloads.”
“Wiz provides a single pane of glass to see what is going on in our cloud environments.”
“We know that if Wiz identifies something as critical, it actually is.”