What is CVE-2026-14925?
The Import WP WordPress plugin before version 2.14.23 lacks authorization checks on an export-file download handler, enabling unauthenticated attackers to download administrator-generated export files containing personal data like email addresses and login names. Immediate update to the latest plugin version is recommended.
Azərbaycanca: Import WP WordPress plugin-in 2.14.23-dən əvvəlki versiyalarında ixrac faylı yükləmə handlerində avtorizasiya yoxlanışı yoxdur. Bu, autentifikasiya olunmamış hücumçulara administrator tərəfindən yaradılan, e-poçt ünvanları və istifadəçi adları kimi şəxsi məlumatları ehtiva edə bilən ixrac fayllarını endirməyə imkan verir. Plugin-i dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What personal data can be leaked through CVE-2026-14925?
Through this vulnerability, unauthenticated attackers can download administrator-generated export files and access personal data such as email addresses and login names.
Which versions of the Import WP plugin are affected by CVE-2026-14925?
The Import WP WordPress plugin versions before 2.14.23 are affected by this vulnerability. Immediate update to the latest plugin version is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.