CVE-2025-14277
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-14277 is a Server-Side Request Forgery (SSRF) vulnerability in the Prime Slider – Addons for Elementor WordPress plugin, developed by BDThemes. It affects all versions up to and including 4.0.9, and was disclosed on December 18, 2025. The flaw allows authenticated attackers with subscriber-level access or above to make arbitrary web requests from the server via the import_elementor_template AJAX action. It carries a CVSS v3.1 base score of 4.3 (Medium), assigned by Wordfence (Red Hat CVE, ENISA EUVD).

Technical details

The vulnerability is classified as CWE-918 (Server-Side Request Forgery) and stems from insufficient validation of user-supplied URLs in the import_elementor_template AJAX action handler. An authenticated attacker with at minimum subscriber-level privileges can supply an arbitrary URL to this endpoint, causing the WordPress server to issue HTTP requests to attacker-controlled or internal destinations. This can be leveraged to probe internal network services, access cloud metadata endpoints (e.g., AWS IMDSv1), or interact with services not otherwise exposed to the internet. No public proof-of-concept exploit code has been identified at this time (Wordfence, ENISA EUVD).

Impact

Successful exploitation allows an authenticated attacker to use the vulnerable WordPress server as a proxy to query internal services, potentially exposing sensitive configuration data, credentials, or cloud instance metadata. The confidentiality impact is rated low, with no direct integrity or availability impact. However, in environments hosted on cloud infrastructure, SSRF can be escalated to retrieve IAM credentials via metadata services, enabling broader account compromise (Red Hat CVE, Wordfence).

Exploitability

No active in-the-wild exploitation has been reported for CVE-2025-14277, and it is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.025%, indicating a low probability of near-term exploitation. Exploitation requires at minimum a valid subscriber-level account on the target WordPress site, limiting opportunistic mass exploitation. No weaponized exploit kits or threat actor attribution have been identified (ENISA EUVD, Wordfence).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Prime Slider – Addons for Elementor plugin (version ≤ 4.0.9) using tools like WPScan or by inspecting plugin directories.
  2. Obtain authenticated access: Register or obtain a subscriber-level (or higher) account on the target WordPress site.
  3. Craft malicious AJAX request: Send an authenticated POST request to the WordPress AJAX endpoint (/wp-admin/admin-ajax.php) with the action parameter set to import_elementor_template and a URL parameter pointing to an internal or attacker-controlled resource (e.g., http://169.254.169.254/latest/meta-data/ for AWS metadata).
  4. Retrieve server response: Analyze the server's response to extract data returned from the internal service, such as cloud credentials, internal API responses, or network topology information.
  5. Escalate if applicable: Use any retrieved credentials or tokens (e.g., AWS IAM keys from metadata) to pivot to broader infrastructure access (Wordfence).

Indicators of compromise

  • Network: Outbound HTTP requests from the WordPress server to internal IP ranges (e.g., 169.254.169.254, 10.0.0.0/8, 192.168.0.0/16) or unexpected external hosts originating from the web server process.
  • Logs: WordPress access logs showing repeated POST requests to /wp-admin/admin-ajax.php with action=import_elementor_template and suspicious or internal URLs as parameters; web server error logs showing connection attempts to internal services.
  • Process: Unusual outbound connections initiated by the PHP-FPM or Apache/Nginx worker processes to non-standard destinations.

Mitigation and workarounds

BDThemes released a patched version of the plugin (4.1.0) that addresses this vulnerability. WordPress site administrators should update the Prime Slider – Addons for Elementor plugin to version 4.1.0 or later immediately via the WordPress plugin dashboard or by applying the changeset directly. As a temporary workaround, restricting subscriber-level user registration or disabling the plugin until patching is feasible can reduce exposure. Web application firewalls (WAFs) with SSRF detection rules can provide additional defense-in-depth (Wordfence, WordPress Changeset).

Community reactions

Sucuri included CVE-2025-14277 in their December 2025 vulnerability patch roundup, noting it as part of a broader set of WordPress plugin issues requiring attention (Sucuri Blog). The vulnerability received standard automated coverage across CVE aggregation platforms and security feeds, with no notable researcher commentary or significant community discussion beyond routine disclosure.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-13784CRITICAL9.8
  • arforms-form-builder
NoYesAug 16, 2026
CVE-2026-17087HIGH7.5
  • wp-travel-engine
NoYesAug 16, 2026
CVE-2026-2497HIGH7.2
  • gallery-plugin
NoYesAug 16, 2026
CVE-2026-17608MEDIUM6.5
  • wp-compress-image-optimizer
NoYesAug 16, 2026
CVE-2026-2357MEDIUM6.4
  • bold-page-builder
NoYesAug 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management