- ‘Motors’ enabled threat actors to take over admin accounts
- This activated full takeover of the site
- The developers released a solution
Motors, a Premium theme for WordPress, wore a vulnerability of critical difficulty that allowed malicious actors to take over compromised sites in full.
The privilege Escalation error due to the theme that is incorrectly validating user identities before updating passwords is now traced as CVE-2025-4322 and has a severity of 9.8/10 (critical).
Security researchers Wordfence, who first discovered this error, explained how threat actors could use it to “change arbitrary user passwords, including administrators, and take advantage of it to access their account.”
Premium themes
Obviously, having access to an admin account gives the malicious actors all kinds of privileges, including complete takeover of sites. All versions up to 5.6.68 are affected. The update relating to the error was released on May 14, 2025. Since themes are not as simple as suspending or swap as plugins, users are advised to update their engines as soon as possible.
Motors is a car dealer WordPress theme, designed for car dealerships, classified listing, auto rental, boats, repair services and motorcycle dealers. It is developed by a company called Stylemixthemes and according to Bleeping computeris one of the best -selling themes of its kind. In the Envato market it sells for $ 79 and has been sold more than 22,300 times.
WordPress is the world’s number a site building platform that operates more than half of all sites on the Internet. This also makes it an important target for cyber criminals, but since it is mostly safe, hackers are looking for utilization in themes and additions used as a springboard for further compromise.
For example, news in early March this year broke out that malicious JavaScript code was inserted into more than 1,000 WordPress websites after compromised extras. Users are advised to keep only the additions they actually use and to keep them up to date at all times.
Via Bleeping computer