
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14166 is a PHP Code Injection vulnerability in the WPMasterToolKit (WPMTK) – All in one plugin for WordPress, affecting all versions up to and including 2.13.0. The flaw allows authenticated attackers with Contributor-level access or above to create and execute arbitrary PHP code via the plugin's Code Snippets feature, due to missing capability checks. It was published on December 12, 2025, with Wordfence credited as the assigner. The CVSS v3.1 base score is 5.3 (Medium), though the actual impact is assessed as HIGH given the potential for remote code execution and full site compromise (Red Hat CVE, Wordfence).
The root cause is classified as CWE-94 (Improper Control of Generation of Code / Code Injection). The vulnerability exists in class-code-snippets.php within the plugin's admin modules, where the Code Snippets feature permits Author-level users to write and execute arbitrary PHP code without enforcing proper WordPress capability checks (lines ~135 and ~628 of the affected file). An authenticated attacker with at minimum Contributor-level access can craft a malicious code snippet and trigger its execution server-side over the network, requiring no user interaction beyond authentication (Wordfence, WordPress Trac).
Successful exploitation enables an authenticated attacker to execute arbitrary PHP code on the underlying server, leading to remote code execution (RCE), privilege escalation to administrator or system-level access, and complete WordPress site compromise. Attackers can exfiltrate sensitive data (database credentials, user data), install backdoors or web shells, deface the site, or pivot to other systems accessible from the web server. All confidentiality, integrity, and availability of the affected WordPress installation are at risk (Red Hat CVE, Wordfence).
No public exploit code or active in-the-wild exploitation has been confirmed as of the available data. The EPSS score is approximately 0.097%, indicating a low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires at minimum a Contributor-level WordPress account, which limits the attack surface compared to unauthenticated vulnerabilities, but the low barrier for registered users on open-registration sites increases risk (Wordfence, Red Hat CVE).
/wp-content/plugins/wpmastertoolkit/).<?php system($_GET['cmd']); ?>).wp-admin/admin-ajax.php or plugin-specific admin pages) from low-privileged user accounts.wp-config.php or other core files.bash, curl, wget, or network scanning tools.Update the WPMasterToolKit plugin to version 2.13.1 or later, which addresses the missing capability checks in the Code Snippets feature. Site administrators should audit existing code snippets for malicious content and review user accounts with Contributor-level access or above. If immediate patching is not possible, consider disabling the Code Snippets module within the plugin settings or restricting access to the WordPress admin dashboard to trusted IP addresses as a temporary workaround (Wordfence, WordPress Trac).
Wordfence disclosed the vulnerability and assigned the CVE, with the finding also tracked by Patchstack and covered by security aggregators including VulDB, Vulners, and CVEFeed. A technical write-up was published by Infinit Security shortly after disclosure. No significant vendor statements beyond the patch release or notable social media controversy has been observed for this CVE.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."