
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14173 is a Missing Authorization vulnerability in the Perfit WooCommerce plugin for WordPress, affecting all versions up to and including 1.0.1. The flaw allows unauthenticated remote attackers to delete arbitrary plugin settings by exploiting missing authorization checks on the logout function. It was published on January 14, 2026, with Wordfence as the reporting CNA. The vulnerability carries a CVSS v3.1 base score of 5.3 (Medium) (Wordfence, Red Hat CVE).
The root cause is CWE-862 (Missing Authorization): the plugin's logout function is called via the actions function hooked to WordPress's admin_init action without performing any capability or authentication checks. Because admin_init fires for all admin-area requests — including unauthenticated ones under certain conditions — an attacker can pass a crafted action parameter to trigger the logout function and delete arbitrary plugin settings. The vulnerable code is located in includes/class-wcp-settings-tab.php at line 102 of version 1.0.1 (Wordfence, WordPress Trac).
Successful exploitation allows unauthenticated attackers to delete or reset the Perfit WooCommerce plugin's configuration settings, which could disrupt e-commerce integrations relying on the plugin (e.g., Perfit marketing platform connectivity). The impact is limited to integrity — there is no confidentiality or availability impact per the CVSS assessment — but loss of plugin settings could cause service disruption for WooCommerce stores dependent on the Perfit integration (Wordfence).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.045% (0.000450), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified (Feedly).
/wp-content/plugins/perfit-woocommerce/./wp-admin/admin-post.php or a similar endpoint that triggers admin_init) with the action parameter set to the value that invokes the logout function within the plugin.logout function executes and deletes the plugin's stored settings./wp-admin/admin-post.php or /wp-admin/) with an action parameter value associated with the Perfit plugin's logout/settings-deletion function.action parameter values, particularly without session cookies or authentication headers.Users should update the Perfit WooCommerce plugin to a version beyond 1.0.1 that includes proper authorization checks on the logout function. If no patched version is yet available from the plugin author, the recommended workaround is to deactivate and remove the plugin until a fix is released. Site administrators can also use a WordPress security plugin (e.g., Wordfence) to monitor and block suspicious requests targeting admin endpoints (Wordfence).
Wordfence disclosed the vulnerability as part of their standard threat intelligence reporting on January 14, 2026. No significant broader media coverage, notable researcher commentary, or social media discussion beyond automated CVE tracking feeds has been identified for this vulnerability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."