If you are using the popular automotive WordPress theme Motors (car dealerships, car rental, vehicle classifieds) and suddenly can't log in because your admin password has been changed — you may have been affected by the CVE-2025-4322 (CVSS 9.8) vulnerability. This is an unauthenticated password reset due to an identity verification error, which allows an attacker to take over the administrator account . The patch was released on 14.5.2025 (version 5.6.68 ), and active attacks have been recorded since June 2025.
Are you affected?
- You can't log in — the administrator password was changed without your knowledge
- Unknown admin accounts or page changes
- Use a Motors theme older than 5.6.68
What to do now
- Update the Motors theme to 5.6.68 or later.
- Take back control of the admin account (via database or hosting) and change all passwords.
- Check for planted files and other admin accounts.
Note: The Motors theme also had a second vulnerability (CVE-2025-64374) — updating to the latest version covers both.
Locked out of your own page? Send us the link — diagnosis is free, and we'll get back to you within 5 minutes. Emergency repair →
WMD — Super fast support.