CVE-2025-14166: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-14166 is a PHP Code Injection vulnerability in the WPMasterToolKit (WPMTK) – All in one plugin for WordPress, affecting all versions up to and including 2.13.0. The flaw allows authenticated attackers with Contributor-level access or above to create and execute arbitrary PHP code via the plugin's Code Snippets feature, due to missing capability checks. It was published on December 12, 2025, with Wordfence credited as the assigner. The CVSS v3.1 base score is 5.3 (Medium), though the actual impact is assessed as HIGH given the potential for remote code execution and full site compromise (Red Hat CVE, Wordfence).

Technical details

The root cause is classified as CWE-94 (Improper Control of Generation of Code / Code Injection). The vulnerability exists in class-code-snippets.php within the plugin's admin modules, where the Code Snippets feature permits Author-level users to write and execute arbitrary PHP code without enforcing proper WordPress capability checks (lines ~135 and ~628 of the affected file). An authenticated attacker with at minimum Contributor-level access can craft a malicious code snippet and trigger its execution server-side over the network, requiring no user interaction beyond authentication (Wordfence, WordPress Trac).

Impact

Successful exploitation enables an authenticated attacker to execute arbitrary PHP code on the underlying server, leading to remote code execution (RCE), privilege escalation to administrator or system-level access, and complete WordPress site compromise. Attackers can exfiltrate sensitive data (database credentials, user data), install backdoors or web shells, deface the site, or pivot to other systems accessible from the web server. All confidentiality, integrity, and availability of the affected WordPress installation are at risk (Red Hat CVE, Wordfence).

Exploitability

No public exploit code or active in-the-wild exploitation has been confirmed as of the available data. The EPSS score is approximately 0.097%, indicating a low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires at minimum a Contributor-level WordPress account, which limits the attack surface compared to unauthenticated vulnerabilities, but the low barrier for registered users on open-registration sites increases risk (Wordfence, Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the WPMasterToolKit plugin version ≤ 2.13.0 using tools like WPScan, Shodan, or manual enumeration of plugin paths (e.g., /wp-content/plugins/wpmastertoolkit/).
  2. Obtain Authenticated Access: Register or compromise a WordPress account with at least Contributor-level privileges on the target site.
  3. Navigate to Code Snippets Feature: Log in and access the WPMasterToolKit Code Snippets module via the WordPress admin dashboard.
  4. Inject Malicious PHP Code: Create a new code snippet containing arbitrary PHP payload, such as a reverse shell or web shell (e.g., <?php system($_GET['cmd']); ?>).
  5. Execute the Snippet: Save and activate/execute the snippet through the plugin interface, which triggers server-side PHP evaluation without proper capability validation.
  6. Achieve Objective: Use the executed code to establish persistence (web shell), escalate privileges, exfiltrate data, or pivot to other systems (Wordfence, WordPress Trac).

Indicators of compromise

  • Logs: WordPress access logs showing authenticated POST requests to admin endpoints associated with the WPMasterToolKit Code Snippets feature (e.g., wp-admin/admin-ajax.php or plugin-specific admin pages) from low-privileged user accounts.
  • File System: Unexpected PHP files or web shells created in the WordPress installation directory or uploads folder; modifications to wp-config.php or other core files.
  • Database: New or modified entries in the WordPress options table or custom plugin tables related to code snippets containing obfuscated or suspicious PHP code.
  • Process: Unusual child processes spawned by the web server process (e.g., Apache/Nginx/PHP-FPM) such as bash, curl, wget, or network scanning tools.
  • Network: Outbound connections from the web server to unknown external IPs or C2 infrastructure, particularly on non-standard ports.

Mitigation and workarounds

Update the WPMasterToolKit plugin to version 2.13.1 or later, which addresses the missing capability checks in the Code Snippets feature. Site administrators should audit existing code snippets for malicious content and review user accounts with Contributor-level access or above. If immediate patching is not possible, consider disabling the Code Snippets module within the plugin settings or restricting access to the WordPress admin dashboard to trusted IP addresses as a temporary workaround (Wordfence, WordPress Trac).

Community reactions

Wordfence disclosed the vulnerability and assigned the CVE, with the finding also tracked by Patchstack and covered by security aggregators including VulDB, Vulners, and CVEFeed. A technical write-up was published by Infinit Security shortly after disclosure. No significant vendor statements beyond the patch release or notable social media controversy has been observed for this CVE.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management