
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-64374 is a critical Unrestricted File Upload vulnerability (CWE-434) in the Motors WordPress theme by StylemixThemes, allowing authenticated attackers to upload and execute malicious files. It affects all versions of the Motors theme up to and including 5.6.81. The vulnerability was published on December 18, 2025, and was assigned by Patchstack. It carries a CVSS v3.1 base score of 9.9 (Critical) (Feedly, Patchstack).
The root cause is classified as CWE-434 (Unrestricted Upload of File with Dangerous Type), meaning the Motors theme fails to properly validate or restrict the file types that authenticated users can upload. An attacker with low-privilege credentials (e.g., a subscriber or contributor account) can upload a file with a dangerous type — such as a PHP web shell — through the theme's file upload functionality. Because the scope is marked as Changed in the CVSS vector, successful exploitation can impact resources beyond the vulnerable component itself, such as the underlying web server and other hosted sites. No specific technical write-up or PoC code has been publicly released at this time (Feedly, Patchstack).
Successful exploitation grants an attacker the ability to upload and execute arbitrary code on the web server, resulting in full compromise of confidentiality, integrity, and availability. An attacker could deploy a web shell to gain persistent remote access, exfiltrate sensitive data (including WordPress database credentials), deface the site, or use the compromised server as a pivot point for lateral movement within the hosting environment. With approximately 20,000 active installations of the Motors theme, the potential attack surface is significant (Patchstack, Infosecurity Magazine).
shell.php) and submit it via the vulnerable upload mechanism, bypassing any client-side restrictions.https://target.com/wp-content/uploads/shell.php) to achieve remote code execution and establish persistent access (Patchstack, Infosecurity Magazine).shell.php, cmd.php) in WordPress upload directories such as wp-content/uploads/ or theme-specific subdirectories; newly created files with unusual names or extensions in web-accessible directories./wp-admin/admin-ajax.php) followed by GET requests to newly created PHP files in upload directories; requests from unusual IP addresses to theme-specific upload handlers.bash, curl, wget, or python; unusual cron jobs added under the web server user account.StylemixThemes has released a patched version of the Motors theme; users should update to version 5.6.82 or later immediately. Site administrators who cannot update immediately should consider temporarily disabling the Motors theme or restricting file upload capabilities via a Web Application Firewall (WAF) rule. Additionally, limiting WordPress user registrations and reviewing existing user accounts for unauthorized low-privilege accounts is recommended as a precautionary measure (Patchstack, Infosecurity Magazine).
Patchstack published a dedicated article highlighting the critical severity of this vulnerability and its potential impact on approximately 20,000 WordPress sites using the Motors theme, emphasizing the risk of complete site takeover (Patchstack). Infosecurity Magazine covered the story, noting the site takeover risk posed by the flaw (Infosecurity Magazine). The vulnerability was also included in The Hacker News weekly security recap, indicating broader industry awareness (The Hacker News).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."