ForensicsS | Private Detective & Digital Forensics Investigation Experts
  • info@forensicss.com

    Send Email

  • 11400 West Olympic Blvd, Los Angeles, CA 90064

  • Home
  • About Us
  • Services
    • Domestic Investigation
      • Los Angeles Private Eye
      • Infidelity Investigations
      • Asset Investigations
      • Private Detective Orange County
      • Child Custody Investigations
      • Missing Person Locates
      • Wire Fraud
      • Corporate Security Investigations
      • Surveillance Operations
      • Financial Fraud Investigations
      • Asset and Hidden Finances Investigations
      • Bug Sweep TSCM Investigation
    • Cyber Security
      • Cyber Bullying Online Investigation
      • Penetration Testing Service
      • Social Media Monitoring
      • Romance Scam Investigator
      • Cyber Stalking Investigation
      • Crypto Scam Investigation
      • Cyber Security Assessment
      • Cyber Harassment Online Investigator
      • Ransomware Attack Investigation
      • Social Media Investigator
      • Extortion Investigation services
      • Background Screening
      • Insurance Fraud Detective
      • Forensic Accounting
      • Online Identity Theft
      • Online Blackmail
      • Cell Phone Forensics
      • Automotive Forensics
      • Audio Video Forensics
      • E-Discovery
      • Computer and Cell Phone Forensics
  • Closed Cases
    • Closed Cases
    • Case Details
  • News
  • Contact
310-270-0598

Confidentiality Guaranteed

310-270-0598

Confidentiality Guaranteed

Logo

Contact Info

  • 11400 West Olympic Blvd, Los Angeles, CA 90064
  • 310-270-0598
  • info@forensicss.com

    Blog Details

      ForensicsS | Private Detective & Digital Forensics Investigation Experts > News > Uncategorized > WordPress Motors theme flaw mass-exploited to hijack admin accounts
    WordPress Motors theme flaw mass-exploited to hijack admin accounts
    21
    Jun
    • ForensicsS
    • 0 Comments

    WordPress Motors theme flaw mass-exploited to hijack admin accounts

    Cybersecurity expert

    cybersecurity expert Hacker

    Hackers are exploiting a severe privilege escalation vulnerability within the WordPress theme “Motors” to hijack administrator accounts and construct complete benefit watch over of a centered dwelling.

    The malicious job changed into once noticed by Wordfence, which had warned closing month in regards to the severity of the flaw, tracked beneath CVE-2025-4322, urging customers to upgrade at once.

    Motors, developed by StylemixThemes, is a WordPress theme in vogue among car-linked websites. It has 22,460 gross sales on the EnvatoMarket and is backed by an active community of customers.

    The privilege escalation vulnerability changed into once found out on Would possibly well perhaps maybe 2, 2025, and first reported by Wordfence on Would possibly well perhaps maybe 19, impacting all variations sooner than and including 5.6.67.

    The flaw arises from an corrupt particular person identification validation at some point soon of password updating, permitting unauthenticated attackers to change administrator passwords at will.

    StylemixThemes launched Motors model 5.6.68, which addresses CVE-2025-4322, on Would possibly well perhaps maybe 14, 2025, but many customers failed to have a look on the change by Wordfence’s disclosure and got exposed to elevated exploitation effort.

    As Wordfence confirms in a brand current writeup, the assaults began on Would possibly well perhaps maybe 20, handiest a day after they publicly disclosed the particulars. Wide-scale assaults were noticed by June 7, 2025, with Wordfence reporting blockading 23,100 makes an wrestle its customers.

    cybersecurity expert Daily attack volumes
    Day-after-day attack volumes
    Supply: Wordfence

    Cybersecurity expert Assault course of and signs of breach

    The vulnerability is within the Motors theme’s “Login Register” widget, including password restoration functionality.

    The attacker first locates the URL where this widget is placed by probing /login-register, /myth, /reset-password, /signin, etc., with specially crafted POST requests till they fetch a success.

    The build a query to comprises invalid UTF-8 characters in a malicious ‘hash_check’ value, inflicting the hash comparison within the password reset logic to be successful incorrectly.

    The POST body comprises a ‘stm_new_password’ value that resets the particular person password, concentrated on particular person IDs that on the total correspond to administrator customers.

    cybersecurity expert Example requests from the attacks
    Instance requests from the assaults
    Supply: Wordfence

    Attacker-home passwords noticed within the assaults up to now comprise: 

    • Testtest123!@#
    • rzkkd$SP3znjrn
    • Kurd@Kurd12123
    • owm9cpXHAZTk
    • db250WJUNEiG

    Once fetch admission to is obtained, the attackers log into the WordPress dashboard as administrators and accomplish current admin accounts for persistence.

    The surprising appearance of such accounts mixed with current administrators being locked out (passwords now no longer working) are signs of CVE-2025-4322 exploitation.

    Wordfence has also listed loads of IP addresses that initiate these assaults within the yarn, which WordPress dwelling homeowners are suggested to placed on their block listing.


    cybersecurity expert Tines Needle

    Cybersecurity expert Why IT teams are ditching handbook patch management

    Patching historical to signify complex scripts, prolonged hours, and never-ending fireplace drills. No longer anymore.

    On this current information, Tines breaks down how as a lot as date IT orgs are leveling up with automation. Patch faster, decrease overhead, and focal point on strategic work — no complex scripts required.

    Learn More

    • Tags

    • cybercrime cybercrimephishing-attack cybersecurity email-fraud forensics|digital-forensics hacker Investigation malware Motors online-scam private-detective scam|fraud private-eye cyber|cybersecurity private-eye phishing|phishing-attack private-investigator private-investigator hacking|hacker WordPress

    Recent Posts

    • University of Virginia President Resigns Underneath Stress From Trump Administration
    • Crypto heists reach $2.1B to this point in 2025 as converse-backed hackers ramp up assaults
    • British man in the lend a hand of ‘IntelBroker’ hacker community charged with stealing millions
    • ‘He must be deported’: Tennessee Congressman requires DOJ probe into Mamdani’s naturalization
    • Colley Intelligence Identified in Chambers Litigation Strengthen Manual 2025

    Recent Comments

    No comments to show.

    Categories

    • cybersecurity
    • Investigations
    • Uncategorized

    Recent Posts

    University of Virginia President Resigns Underneath Stress From Trump Administration
    June 27, 2025
    University of Virginia President Resigns Underneath Stress From Trump Administration
    Crypto heists reach $2.1B to this point in 2025 as converse-backed hackers ramp up assaults
    June 27, 2025
    Crypto heists reach $2.1B to this point in 2025 as converse-backed hackers ramp up assaults
    British man in the lend a hand of ‘IntelBroker’ hacker community charged with stealing millions
    June 27, 2025
    British man in the lend a hand of ‘IntelBroker’ hacker community charged with stealing millions

    Popular Tags

    accused administration calls Crypto Cyber cybercrime cybercrimefraud cybercrimehacker cybercrimephishing-attack cybersecurity digital-forensics director email-fraud Extortion forensics|digital-forensics fraud government hacker hackers Investigation investigationcybersecurity Korea Korean Launches malware malwarefraud malwarephishing-attack Million North online-scam online-scamphishing-attack orders Patel phishing-attack private-detective scam|fraud private-eye cyber|cybersecurity private-eye phishing|phishing-attack private-investigator private-investigator hacking|hacker probe regulator suspect Trump University warns

    Forensics – Trusted Experts in Surveillance, Cyber Security, Background Checks, and Digital Forensics across California.

    • 310-270-0598
    • info@forensicss.com
    • 11400 West Olympic Blvd, Los Angeles, CA 90064

    Explore

    • News
    • About
    • Our Services
    • Find A Person
    • Child Custody
    • Contact Us
    • Los Angeles
    • Orange County
    • San Diego

    Services

    • Cyber Security
    • Online Blackmail
    • Cell Phone Forensics
    • Domestic Investigation
    • Social Media Investigator
    • Crypto Scam Investigation

    Newsletter

    Sign up email to get our daily latest news & updates from us

    © Copyright 2021 by KRIGO