
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14348 is an authorization bypass vulnerability in the weMail WordPress plugin (versions up to and including 2.0.7) that allows unauthenticated attackers to impersonate admin users and exfiltrate subscriber PII. The flaw was disclosed on January 20, 2026, and was reported by Wordfence. It carries a CVSS v3.1 base score of 5.3 (Medium), assigned by Wordfence (Wordfence).
The root cause is CWE-285 (Improper Authorization): the plugin's REST API blindly trusts the x-wemail-user HTTP header to identify and authenticate users without verifying that the request originates from a legitimate, authenticated WordPress session. An attacker can supply any admin email address in this header to impersonate that user. Admin email addresses are trivially enumerable via the unauthenticated WordPress REST API endpoint /wp-json/wp/v2/users. The vulnerable code paths are located in includes/Rest/Csv.php at lines 79 and 85 of the 2.0.6 tag (Wordfence, WordPress Trac).
Successful exploitation allows unauthenticated remote attackers to access CSV subscriber endpoints and exfiltrate personally identifiable information (PII) including subscriber email addresses, names, and phone numbers from imported CSV files. The impact is limited to confidentiality — there is no integrity or availability impact — but the exposure of subscriber PII can have significant privacy and regulatory consequences (e.g., GDPR violations) for affected site operators (Wordfence).
No public exploit code or active in-the-wild exploitation has been reported as of the time of disclosure. The EPSS score is approximately 0.038%, indicating a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the attack requires no authentication, no user interaction, and no special privileges, and the prerequisite (admin email enumeration) is trivially achievable via the public WordPress REST API, making the barrier to exploitation very low (Wordfence).
GET /wp-json/wp/v2/users) to retrieve registered user accounts, including admin email addresses.x-wemail-user HTTP header (e.g., x-wemail-user: admin@example.com)./wp-json/wp/v2/users followed shortly by requests to weMail CSV REST API endpoints from the same source IP; requests to weMail REST API endpoints containing the x-wemail-user header from unauthenticated sessions./wp-json/wemail/v1/subscribers/csv or similar) with no associated WordPress authentication cookies; repeated enumeration of /wp-json/wp/v2/users from a single IP.Users should update the weMail plugin to a version beyond 2.0.7 that includes the fix introduced in the changeset patching the Csv.php authorization logic. The patch can be reviewed in the WordPress plugin repository changeset (WordPress Changeset). As a temporary workaround, site administrators can restrict access to the WordPress REST API for unauthenticated users using a security plugin or server-level rules, and disable the /wp-json/wp/v2/users endpoint to prevent admin email enumeration (Wordfence).
Wordfence identified and disclosed the vulnerability, providing the CVE assignment and technical details. No significant broader media coverage or notable researcher commentary beyond the initial Wordfence disclosure has been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."