
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14037 is an arbitrary file deletion vulnerability via path traversal in the Invelity Product Feeds plugin for WordPress. It affects all versions up to and including 1.2.6, stemming from missing input validation and sanitization in the createManageFeedPage function. The vulnerability was published on March 21, 2026, and assigned by Wordfence. It carries a CVSS v3.1 base score of 8.1 (High) (Wordfence, Feedly).
The root cause is classified as CWE-22 (Path Traversal) combined with CWE-352 (Cross-Site Request Forgery). The createManageFeedPage function in the plugin fails to validate or sanitize user-supplied input, allowing path traversal sequences (e.g., ../../) to escape the intended directory and reference arbitrary files on the server. Exploitation requires an authenticated administrator-level session, but the CSRF component means an attacker can craft a malicious link and trick an admin into clicking it, triggering the file deletion without direct attacker access to the admin panel. The vulnerable code is visible in the plugin's source at classPluginSettingsManageFeedPage.php around line 60 (Wordfence, Plugin Source).
Successful exploitation allows an attacker to delete arbitrary files on the web server, including critical WordPress core files, configuration files (e.g., wp-config.php), or other sensitive data. This can result in website defacement, loss of site functionality, exposure of database credentials if configuration files are deleted and regenerated insecurely, or complete site compromise. The integrity and availability impacts are rated High, while there is no direct confidentiality impact from this specific vulnerability (Wordfence, Feedly).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.036%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires social engineering an administrator into clicking a malicious link, which raises the bar compared to fully unauthenticated attacks (Wordfence, Feedly).
createManageFeedPage function with path traversal sequences (e.g., ../../wp-config.php) in the file parameter to reference a target file outside the intended directory.wp-config.php, .htaccess, or core WordPress files), the attacker may cause site outage, force re-installation exposing database credentials, or facilitate further compromise (Wordfence, Plugin Source).../../, %2e%2e%2f) in parameters associated with createManageFeedPage.wp-config.php, .htaccess, or WordPress core files; timestamps of file deletions correlating with suspicious admin activity.No patched version of the Invelity Product Feeds plugin beyond 1.2.6 has been confirmed available at the time of disclosure. As an immediate workaround, administrators should deactivate and remove the plugin until a patched version is released. Access to the WordPress admin panel should be restricted to trusted IP addresses, and multi-factor authentication should be enforced for all administrator accounts. Administrators should be educated about phishing and social engineering attacks to reduce the risk of CSRF exploitation. File integrity monitoring tools should be deployed to detect unauthorized file deletions (Wordfence, Wordfence Weekly Report).
Wordfence disclosed the vulnerability as part of their weekly WordPress vulnerability report for the week of March 16–22, 2026, and published a threat intelligence entry with full details. The vulnerability received brief coverage on social media platforms including Mastodon and Bluesky, as well as aggregation by RedPacket Security. No significant researcher commentary or broader media coverage has been identified beyond routine vulnerability aggregation (Wordfence Weekly Report, RedPacket Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."