CVE-2025-14173
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-14173 is a Missing Authorization vulnerability in the Perfit WooCommerce plugin for WordPress, affecting all versions up to and including 1.0.1. The flaw allows unauthenticated remote attackers to delete arbitrary plugin settings by exploiting missing authorization checks on the logout function. It was published on January 14, 2026, with Wordfence as the reporting CNA. The vulnerability carries a CVSS v3.1 base score of 5.3 (Medium) (Wordfence, Red Hat CVE).

Technical details

The root cause is CWE-862 (Missing Authorization): the plugin's logout function is called via the actions function hooked to WordPress's admin_init action without performing any capability or authentication checks. Because admin_init fires for all admin-area requests — including unauthenticated ones under certain conditions — an attacker can pass a crafted action parameter to trigger the logout function and delete arbitrary plugin settings. The vulnerable code is located in includes/class-wcp-settings-tab.php at line 102 of version 1.0.1 (Wordfence, WordPress Trac).

Impact

Successful exploitation allows unauthenticated attackers to delete or reset the Perfit WooCommerce plugin's configuration settings, which could disrupt e-commerce integrations relying on the plugin (e.g., Perfit marketing platform connectivity). The impact is limited to integrity — there is no confidentiality or availability impact per the CVSS assessment — but loss of plugin settings could cause service disruption for WooCommerce stores dependent on the Perfit integration (Wordfence).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.045% (0.000450), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified (Feedly).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Perfit WooCommerce plugin (version ≤ 1.0.1) using tools like WPScan or by checking publicly accessible plugin metadata at /wp-content/plugins/perfit-woocommerce/.
  2. Craft malicious request: Construct an HTTP GET or POST request targeting the WordPress admin area (e.g., /wp-admin/admin-post.php or a similar endpoint that triggers admin_init) with the action parameter set to the value that invokes the logout function within the plugin.
  3. Trigger unauthorized function: Submit the crafted request without any authentication credentials. Because no authorization check is performed, the logout function executes and deletes the plugin's stored settings.
  4. Confirm impact: Verify that the Perfit WooCommerce plugin settings have been cleared, disrupting the store's integration with the Perfit marketing platform (Wordfence, WordPress Trac).

Indicators of compromise

  • Logs: WordPress access logs showing unauthenticated requests to admin endpoints (e.g., /wp-admin/admin-post.php or /wp-admin/) with an action parameter value associated with the Perfit plugin's logout/settings-deletion function.
  • Application: Sudden disappearance or reset of Perfit WooCommerce plugin settings in the WordPress admin panel without any administrator action.
  • Network: Repeated HTTP requests from a single IP to WordPress admin endpoints with plugin-specific action parameter values, particularly without session cookies or authentication headers.

Mitigation and workarounds

Users should update the Perfit WooCommerce plugin to a version beyond 1.0.1 that includes proper authorization checks on the logout function. If no patched version is yet available from the plugin author, the recommended workaround is to deactivate and remove the plugin until a fix is released. Site administrators can also use a WordPress security plugin (e.g., Wordfence) to monitor and block suspicious requests targeting admin endpoints (Wordfence).

Community reactions

Wordfence disclosed the vulnerability as part of their standard threat intelligence reporting on January 14, 2026. No significant broader media coverage, notable researcher commentary, or social media discussion beyond automated CVE tracking feeds has been identified for this vulnerability.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-77115HIGH7.1
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-77116MEDIUM4.3
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-14853MEDIUM4.3
  • woocommerce-bookings
NoYesAug 23, 2026
CVE-2026-77003LOW2.7
  • content-mask
NoYesAug 23, 2026
CVE-2026-13598NONEN/A
  • restrictmate
NoYesAug 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management