
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14064 is a Missing Authorization vulnerability in the BuddyTask plugin for WordPress, affecting all versions up to and including 1.3.0. The flaw allows authenticated attackers with Subscriber-level access or above to perform unauthorized access and modification of task board data across any BuddyPress group, including private and hidden groups they are not members of. It was published on December 12, 2025, and assigned a CVSS v3.1 base score of 5.4 (Medium) (Feedly, Wordfence).
The root cause is CWE-862 (Missing Authorization): multiple AJAX endpoints in the BuddyTask plugin fail to perform capability checks before executing sensitive operations (CWE). Specifically, the vulnerable code is present in buddytask.php at lines 458, 666, 763, and 840, where AJAX handlers for task board operations do not verify whether the requesting user has the necessary permissions to interact with a given BuddyPress group (EUVD). An attacker only needs a valid WordPress account at Subscriber level or above to craft AJAX requests targeting these endpoints, with no additional preconditions required (Wordfence).
Successful exploitation allows authenticated low-privileged users to view, create, modify, and delete task boards belonging to any BuddyPress group — including private and hidden groups they are not members of. This results in both confidentiality and integrity impacts: sensitive group task data may be exposed to unauthorized users, and task boards can be tampered with or destroyed. Availability is not directly impacted, but deletion of task boards constitutes a data integrity risk (Feedly, Wordfence).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported for CVE-2025-14064. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.033%, indicating a low probability of exploitation in the near term (Feedly). Exploitation requires a valid WordPress account, which limits the attack surface compared to unauthenticated vulnerabilities.
/wp-content/plugins/buddytask/.plugins.trac.wordpress.org) to identify vulnerable AJAX action names registered in buddytask.php at lines 458, 666, 763, and 840.wp-admin/admin-ajax.php with the appropriate action parameter corresponding to a task board operation (e.g., view, create, modify, or delete), supplying the target BuddyPress group ID — including IDs for private or hidden groups.wp-admin/admin-ajax.php with BuddyTask-specific action parameters from accounts with low privilege levels (e.g., Subscriber); requests targeting group IDs that the authenticated user is not a member of.admin-ajax.php POST requests from Subscriber-level users at unusual frequency or targeting multiple group IDs; server-side logs reflecting task board creation, modification, or deletion events not initiated by group members or administrators.The vulnerability is patched in BuddyTask version 1.3.1, which adds proper capability checks to the affected AJAX endpoints (Wordfence, WordPress Changeset). Site administrators should update the BuddyTask plugin to version 1.3.1 or later immediately. As a temporary workaround, disabling the BuddyTask plugin until the update can be applied will eliminate the attack surface.
Wordfence disclosed the vulnerability as part of their weekly WordPress vulnerability report for December 8–14, 2025, and assigned it through their threat intelligence program (Wordfence Blog). The vulnerability was also tracked by ENISA's EUVD and noted on social platforms such as Mastodon's vulnerability lookup feed. No significant broader media coverage or notable researcher commentary beyond standard disclosure channels has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."