CVE-2025-14064
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-14064 is a Missing Authorization vulnerability in the BuddyTask plugin for WordPress, affecting all versions up to and including 1.3.0. The flaw allows authenticated attackers with Subscriber-level access or above to perform unauthorized access and modification of task board data across any BuddyPress group, including private and hidden groups they are not members of. It was published on December 12, 2025, and assigned a CVSS v3.1 base score of 5.4 (Medium) (Feedly, Wordfence).

Technical details

The root cause is CWE-862 (Missing Authorization): multiple AJAX endpoints in the BuddyTask plugin fail to perform capability checks before executing sensitive operations (CWE). Specifically, the vulnerable code is present in buddytask.php at lines 458, 666, 763, and 840, where AJAX handlers for task board operations do not verify whether the requesting user has the necessary permissions to interact with a given BuddyPress group (EUVD). An attacker only needs a valid WordPress account at Subscriber level or above to craft AJAX requests targeting these endpoints, with no additional preconditions required (Wordfence).

Impact

Successful exploitation allows authenticated low-privileged users to view, create, modify, and delete task boards belonging to any BuddyPress group — including private and hidden groups they are not members of. This results in both confidentiality and integrity impacts: sensitive group task data may be exposed to unauthorized users, and task boards can be tampered with or destroyed. Availability is not directly impacted, but deletion of task boards constitutes a data integrity risk (Feedly, Wordfence).

Exploitability

No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported for CVE-2025-14064. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.033%, indicating a low probability of exploitation in the near term (Feedly). Exploitation requires a valid WordPress account, which limits the attack surface compared to unauthenticated vulnerabilities.

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the BuddyTask plugin (version ≤ 1.3.0) with BuddyPress enabled, using tools like WPScan or by checking plugin metadata at /wp-content/plugins/buddytask/.
  2. Obtain low-privileged account: Register or use an existing Subscriber-level (or higher) WordPress account on the target site.
  3. Identify AJAX endpoints: Review the plugin source code (publicly available at plugins.trac.wordpress.org) to identify vulnerable AJAX action names registered in buddytask.php at lines 458, 666, 763, and 840.
  4. Craft malicious AJAX request: Send an authenticated HTTP POST request to wp-admin/admin-ajax.php with the appropriate action parameter corresponding to a task board operation (e.g., view, create, modify, or delete), supplying the target BuddyPress group ID — including IDs for private or hidden groups.
  5. Access or manipulate target data: The server processes the request without authorization checks, returning or modifying task board data for the specified group, regardless of the attacker's membership status (Wordfence).

Indicators of compromise

  • Network: Repeated authenticated POST requests to wp-admin/admin-ajax.php with BuddyTask-specific action parameters from accounts with low privilege levels (e.g., Subscriber); requests targeting group IDs that the authenticated user is not a member of.
  • Logs: WordPress access logs showing admin-ajax.php POST requests from Subscriber-level users at unusual frequency or targeting multiple group IDs; server-side logs reflecting task board creation, modification, or deletion events not initiated by group members or administrators.
  • Application: Unexpected changes to task boards in private or hidden BuddyPress groups; task boards appearing, disappearing, or being modified without corresponding group member activity.

Mitigation and workarounds

The vulnerability is patched in BuddyTask version 1.3.1, which adds proper capability checks to the affected AJAX endpoints (Wordfence, WordPress Changeset). Site administrators should update the BuddyTask plugin to version 1.3.1 or later immediately. As a temporary workaround, disabling the BuddyTask plugin until the update can be applied will eliminate the attack surface.

Community reactions

Wordfence disclosed the vulnerability as part of their weekly WordPress vulnerability report for December 8–14, 2025, and assigned it through their threat intelligence program (Wordfence Blog). The vulnerability was also tracked by ENISA's EUVD and noted on social platforms such as Mastodon's vulnerability lookup feed. No significant broader media coverage or notable researcher commentary beyond standard disclosure channels has been observed.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-18044NONEN/A
  • estatik
NoYesAug 12, 2026
CVE-2026-17008NONEN/A
  • quick-paypal-payments
NoNoAug 12, 2026
CVE-2026-16990NONEN/A
  • wp-paypal
NoNoAug 12, 2026
CVE-2026-16747NONEN/A
  • kirki
NoYesAug 12, 2026
CVE-2026-16621NONEN/A
  • woo-paypal-gateway
NoYesAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management