AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2022-3989

HIGH · CVSS 8.8 EPSS 1.05%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2022-12-12 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2022-3989
Severity
HIGH
CVSS
8.8
EPSS
1.05%
WordPress

Original NVD Description

The Motors WordPress plugin before 1.4.4 does not properly validate uploaded files for dangerous file types (such as .php) in an AJAX action, allowing an attacker to sign up on a victim's WordPress instance, upload a malicious PHP file and attempt to launch a brute-force attack to discover the uploaded payload.