
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14277 is a Server-Side Request Forgery (SSRF) vulnerability in the Prime Slider – Addons for Elementor WordPress plugin, developed by BDThemes. It affects all versions up to and including 4.0.9, and was disclosed on December 18, 2025. The flaw allows authenticated attackers with subscriber-level access or above to make arbitrary web requests from the server via the import_elementor_template AJAX action. It carries a CVSS v3.1 base score of 4.3 (Medium), assigned by Wordfence (Red Hat CVE, ENISA EUVD).
The vulnerability is classified as CWE-918 (Server-Side Request Forgery) and stems from insufficient validation of user-supplied URLs in the import_elementor_template AJAX action handler. An authenticated attacker with at minimum subscriber-level privileges can supply an arbitrary URL to this endpoint, causing the WordPress server to issue HTTP requests to attacker-controlled or internal destinations. This can be leveraged to probe internal network services, access cloud metadata endpoints (e.g., AWS IMDSv1), or interact with services not otherwise exposed to the internet. No public proof-of-concept exploit code has been identified at this time (Wordfence, ENISA EUVD).
Successful exploitation allows an authenticated attacker to use the vulnerable WordPress server as a proxy to query internal services, potentially exposing sensitive configuration data, credentials, or cloud instance metadata. The confidentiality impact is rated low, with no direct integrity or availability impact. However, in environments hosted on cloud infrastructure, SSRF can be escalated to retrieve IAM credentials via metadata services, enabling broader account compromise (Red Hat CVE, Wordfence).
No active in-the-wild exploitation has been reported for CVE-2025-14277, and it is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.025%, indicating a low probability of near-term exploitation. Exploitation requires at minimum a valid subscriber-level account on the target WordPress site, limiting opportunistic mass exploitation. No weaponized exploit kits or threat actor attribution have been identified (ENISA EUVD, Wordfence).
/wp-admin/admin-ajax.php) with the action parameter set to import_elementor_template and a URL parameter pointing to an internal or attacker-controlled resource (e.g., http://169.254.169.254/latest/meta-data/ for AWS metadata).169.254.169.254, 10.0.0.0/8, 192.168.0.0/16) or unexpected external hosts originating from the web server process./wp-admin/admin-ajax.php with action=import_elementor_template and suspicious or internal URLs as parameters; web server error logs showing connection attempts to internal services.BDThemes released a patched version of the plugin (4.1.0) that addresses this vulnerability. WordPress site administrators should update the Prime Slider – Addons for Elementor plugin to version 4.1.0 or later immediately via the WordPress plugin dashboard or by applying the changeset directly. As a temporary workaround, restricting subscriber-level user registration or disabling the plugin until patching is feasible can reduce exposure. Web application firewalls (WAFs) with SSRF detection rules can provide additional defense-in-depth (Wordfence, WordPress Changeset).
Sucuri included CVE-2025-14277 in their December 2025 vulnerability patch roundup, noting it as part of a broader set of WordPress plugin issues requiring attention (Sucuri Blog). The vulnerability received standard automated coverage across CVE aggregation platforms and security feeds, with no notable researcher commentary or significant community discussion beyond routine disclosure.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."