CVE-2025-14070
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-14070 is a missing authorization vulnerability in the Reviewify (Review Discounts & Photo/Video Reviews for WooCommerce) plugin for WordPress, developed by xfinitysoft. The flaw allows authenticated attackers with Contributor-level access or above to create arbitrary WooCommerce discount coupons by exploiting a missing capability check on the send_test_email AJAX action. All versions up to and including 1.0.7 are affected. The CVE was published on January 7, 2026, and the description was later updated on April 8, 2026, to extend the affected version range from 1.0.6 to 1.0.7. It carries a CVSS v3.1 base score of 7.5 (High), assigned by Wordfence (Wordfence, NVD).

Technical details

The root cause is classified as CWE-862 (Missing Authorization): the plugin's send_test_email AJAX handler in admin/class-xswcrd-review-discounts-admin.php (around line 425) does not perform a capability check before executing coupon-creation logic (NVD, WordPress Trac). An authenticated user with at minimum Contributor-level access can send a crafted AJAX request to the vulnerable action and trigger WooCommerce coupon creation without any privilege validation. The attack requires network access and a valid WordPress account but no special configuration, making it straightforward to exploit in multi-author or open-registration WordPress environments.

Impact

Successful exploitation allows low-privileged authenticated users to create arbitrary WooCommerce discount coupons, which can be used to purchase products at heavily discounted or zero-cost prices, causing direct financial loss to the store operator (Wordfence). The impact is primarily an integrity violation — there is no confidentiality or availability impact — but the financial consequences for e-commerce stores can be significant. The vulnerability does not enable remote code execution or lateral movement beyond the WordPress/WooCommerce application layer.

Exploitability

No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the available data. The EPSS score is approximately 0.028% (0.000280), indicating a very low probability of exploitation in the near term (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation does require a valid WordPress account with at least Contributor-level access, which limits the attacker pool compared to unauthenticated vulnerabilities.

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Reviewify (review-for-discount) plugin version ≤1.0.7 with WooCommerce enabled. This can be done by checking plugin metadata in page source or using tools like WPScan.
  2. Obtain Contributor access: Register or use an existing Contributor-level (or higher) WordPress account on the target site. Many WordPress sites allow open user registration.
  3. Craft the AJAX request: Prepare an HTTP POST request targeting the WordPress AJAX endpoint (/wp-admin/admin-ajax.php) with the action parameter set to send_test_email and any required nonce or form fields.
  4. Submit the request: Send the crafted request while authenticated. Because no capability check is performed, the server processes the request and creates a WooCommerce discount coupon with attacker-specified parameters (e.g., 100% discount).
  5. Abuse the coupon: Use the generated coupon code during checkout to obtain products at a fraudulent discount, causing financial loss to the store (Wordfence, NVD).

Indicators of compromise

  • Logs: WordPress access logs showing authenticated POST requests to /wp-admin/admin-ajax.php with action=send_test_email from Contributor-level user accounts, especially in high frequency or outside normal business hours.
  • WooCommerce: Unexpected or anomalous discount coupons appearing in the WooCommerce coupon list (WooCommerce > Coupons) that were not created by administrators or shop managers.
  • Logs: WooCommerce order logs showing orders completed with unusually high discount percentages or zero-cost transactions tied to suspicious coupon codes.
  • User Activity: Contributor-level users accessing admin AJAX endpoints they would not normally interact with, visible in server access logs.

Mitigation and workarounds

The vulnerability was patched in the changeset available at the WordPress plugin repository (WordPress Changeset). Store operators should update the Reviewify plugin to the latest version beyond 1.0.7 immediately. As a temporary workaround, site administrators can disable the plugin until a patched version is applied, or restrict user registration to prevent untrusted Contributor-level accounts. Reviewing WooCommerce coupons for unauthorized entries is also recommended as a post-incident check (Wordfence).

Community reactions

Wordfence, which discovered and reported the vulnerability, published it in their weekly WordPress vulnerability report for January 5–11, 2026 (Wordfence Blog). The vulnerability received routine coverage from security aggregators such as RedPacket Security and TheHackerWire on social media platforms including Mastodon and Bluesky, but no significant broader media coverage or notable researcher commentary was observed beyond standard vulnerability disclosure channels.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-78570CRITICAL9.8
  • totaldonations
NoNoAug 25, 2026
CVE-2026-78568CRITICAL9.8
  • totaldonations
NoNoAug 25, 2026
CVE-2026-78572HIGH8.1
  • kalles-addons
NoNoAug 25, 2026
CVE-2026-78576HIGH7.5
  • readabler
NoYesAug 25, 2026
CVE-2026-76128MEDIUM6.4
  • ecommerce-product-catalog
NoYesAug 25, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management