Import WP < 2.14.23 - Unauthenticated Sensitive Information Exposure via Export File Download
Summary
| CVE | CVE-2026-14925 |
|---|---|
| State | PUBLISHED |
| Assigner | WPScan |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-12 06:17:54 UTC |
| Updated | 2026-08-12 06:17:54 UTC |
| Description | The Import WP WordPress plugin before 2.14.23 does not perform any authorization check on one of its export-file download handlers, allowing unauthenticated attackers to download export files generated by administrators, which may contain user personal data such as email addresses, login names and roles. Exploitation requires an unconsumed export to already exist and a low-entropy, time-based download key to be obtained. |
Risk And Classification
Problem Types: CWE-200 Information Exposure
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| wpscan.com/vulnerability/67be2cc3-06d3-419e-8ca4-6dad442a02ca | [email protected] | wpscan.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Muni Nitish Kumar Yaddala (en)
CNA: WPScan (en)
There are currently no legacy QID mappings associated with this CVE.