CVE-2025-14037: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-14037 is an arbitrary file deletion vulnerability via path traversal in the Invelity Product Feeds plugin for WordPress. It affects all versions up to and including 1.2.6, stemming from missing input validation and sanitization in the createManageFeedPage function. The vulnerability was published on March 21, 2026, and assigned by Wordfence. It carries a CVSS v3.1 base score of 8.1 (High) (Wordfence, Feedly).

Technical details

The root cause is classified as CWE-22 (Path Traversal) combined with CWE-352 (Cross-Site Request Forgery). The createManageFeedPage function in the plugin fails to validate or sanitize user-supplied input, allowing path traversal sequences (e.g., ../../) to escape the intended directory and reference arbitrary files on the server. Exploitation requires an authenticated administrator-level session, but the CSRF component means an attacker can craft a malicious link and trick an admin into clicking it, triggering the file deletion without direct attacker access to the admin panel. The vulnerable code is visible in the plugin's source at classPluginSettingsManageFeedPage.php around line 60 (Wordfence, Plugin Source).

Impact

Successful exploitation allows an attacker to delete arbitrary files on the web server, including critical WordPress core files, configuration files (e.g., wp-config.php), or other sensitive data. This can result in website defacement, loss of site functionality, exposure of database credentials if configuration files are deleted and regenerated insecurely, or complete site compromise. The integrity and availability impacts are rated High, while there is no direct confidentiality impact from this specific vulnerability (Wordfence, Feedly).

Exploitability

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.036%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires social engineering an administrator into clicking a malicious link, which raises the bar compared to fully unauthenticated attacks (Wordfence, Feedly).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Invelity Product Feeds plugin version ≤1.2.6 using tools like WPScan or by inspecting publicly accessible plugin metadata.
  2. Craft malicious request: Construct a specially crafted HTTP request targeting the createManageFeedPage function with path traversal sequences (e.g., ../../wp-config.php) in the file parameter to reference a target file outside the intended directory.
  3. Social engineering: Embed the malicious request as a link (exploiting the CSRF weakness) in a phishing email, comment, or message directed at a WordPress administrator of the target site.
  4. Trigger file deletion: When the administrator clicks the link while authenticated, the browser sends the crafted request with the admin's session credentials, causing the plugin to delete the specified arbitrary file on the server.
  5. Achieve objective: Depending on the deleted file (e.g., wp-config.php, .htaccess, or core WordPress files), the attacker may cause site outage, force re-installation exposing database credentials, or facilitate further compromise (Wordfence, Plugin Source).

Indicators of compromise

  • Logs: WordPress access logs showing admin-authenticated POST or GET requests to plugin admin pages with path traversal sequences (e.g., ../../, %2e%2e%2f) in parameters associated with createManageFeedPage.
  • File System: Unexpected disappearance of critical files such as wp-config.php, .htaccess, or WordPress core files; timestamps of file deletions correlating with suspicious admin activity.
  • Logs: WordPress error logs or PHP logs indicating file operation failures or missing files shortly after admin login events from unfamiliar IP addresses.
  • Network: Admin panel requests originating from unusual IP addresses or user agents, particularly if the referrer header is absent or points to an external domain (indicative of CSRF exploitation).

Mitigation and workarounds

No patched version of the Invelity Product Feeds plugin beyond 1.2.6 has been confirmed available at the time of disclosure. As an immediate workaround, administrators should deactivate and remove the plugin until a patched version is released. Access to the WordPress admin panel should be restricted to trusted IP addresses, and multi-factor authentication should be enforced for all administrator accounts. Administrators should be educated about phishing and social engineering attacks to reduce the risk of CSRF exploitation. File integrity monitoring tools should be deployed to detect unauthorized file deletions (Wordfence, Wordfence Weekly Report).

Community reactions

Wordfence disclosed the vulnerability as part of their weekly WordPress vulnerability report for the week of March 16–22, 2026, and published a threat intelligence entry with full details. The vulnerability received brief coverage on social media platforms including Mastodon and Bluesky, as well as aggregation by RedPacket Security. No significant researcher commentary or broader media coverage has been identified beyond routine vulnerability aggregation (Wordfence Weekly Report, RedPacket Security).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management