The Motors WordPress plugin before 1.4.4 does not properly validate uploaded files for dangerous file types (such as .php) in an AJAX action, allowing an attacker to sign up on a victim's WordPress instance, upload a malicious PHP file and attempt to launch a brute-force attack to discover the uploaded payload.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: WPScan

Published: 2022-12-12T17:54:58.545Z

Updated:

Reserved: 2022-11-14T14:45:02.983Z


Link: CVE-2022-3989

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2022-12-12T18:15:12.553

Modified: 2023-11-07T03:52:04.693


Link: CVE-2022-3989

JSON object: View

cve-icon Redhat Information

No data.

CWE

No CWE.