CVE-2025-14348: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-14348 is an authorization bypass vulnerability in the weMail WordPress plugin (versions up to and including 2.0.7) that allows unauthenticated attackers to impersonate admin users and exfiltrate subscriber PII. The flaw was disclosed on January 20, 2026, and was reported by Wordfence. It carries a CVSS v3.1 base score of 5.3 (Medium), assigned by Wordfence (Wordfence).

Technical details

The root cause is CWE-285 (Improper Authorization): the plugin's REST API blindly trusts the x-wemail-user HTTP header to identify and authenticate users without verifying that the request originates from a legitimate, authenticated WordPress session. An attacker can supply any admin email address in this header to impersonate that user. Admin email addresses are trivially enumerable via the unauthenticated WordPress REST API endpoint /wp-json/wp/v2/users. The vulnerable code paths are located in includes/Rest/Csv.php at lines 79 and 85 of the 2.0.6 tag (Wordfence, WordPress Trac).

Impact

Successful exploitation allows unauthenticated remote attackers to access CSV subscriber endpoints and exfiltrate personally identifiable information (PII) including subscriber email addresses, names, and phone numbers from imported CSV files. The impact is limited to confidentiality — there is no integrity or availability impact — but the exposure of subscriber PII can have significant privacy and regulatory consequences (e.g., GDPR violations) for affected site operators (Wordfence).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported as of the time of disclosure. The EPSS score is approximately 0.038%, indicating a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the attack requires no authentication, no user interaction, and no special privileges, and the prerequisite (admin email enumeration) is trivially achievable via the public WordPress REST API, making the barrier to exploitation very low (Wordfence).

Exploitation steps

  1. Enumerate admin emails: Query the target WordPress site's public REST API endpoint (GET /wp-json/wp/v2/users) to retrieve registered user accounts, including admin email addresses.
  2. Identify the vulnerable plugin: Confirm the weMail plugin (version ≤ 2.0.7) is installed by checking plugin-specific REST API routes or observable site behavior.
  3. Craft a malicious request: Send an HTTP request to the weMail CSV subscriber REST API endpoint, injecting the enumerated admin email into the x-wemail-user HTTP header (e.g., x-wemail-user: admin@example.com).
  4. Bypass authorization: The plugin trusts the supplied header without session verification, granting the attacker admin-level access to the CSV endpoints.
  5. Exfiltrate subscriber PII: Retrieve the CSV subscriber data, which may include names, email addresses, and phone numbers of all imported subscribers (Wordfence, WordPress Trac).

Indicators of compromise

  • Network: Unauthenticated HTTP GET requests to /wp-json/wp/v2/users followed shortly by requests to weMail CSV REST API endpoints from the same source IP; requests to weMail REST API endpoints containing the x-wemail-user header from unauthenticated sessions.
  • Logs: WordPress access logs showing REST API calls to weMail CSV endpoints (e.g., /wp-json/wemail/v1/subscribers/csv or similar) with no associated WordPress authentication cookies; repeated enumeration of /wp-json/wp/v2/users from a single IP.
  • Application: Unexpected or high-volume downloads of subscriber CSV data outside of normal administrative activity.

Mitigation and workarounds

Users should update the weMail plugin to a version beyond 2.0.7 that includes the fix introduced in the changeset patching the Csv.php authorization logic. The patch can be reviewed in the WordPress plugin repository changeset (WordPress Changeset). As a temporary workaround, site administrators can restrict access to the WordPress REST API for unauthenticated users using a security plugin or server-level rules, and disable the /wp-json/wp/v2/users endpoint to prevent admin email enumeration (Wordfence).

Community reactions

Wordfence identified and disclosed the vulnerability, providing the CVE assignment and technical details. No significant broader media coverage or notable researcher commentary beyond the initial Wordfence disclosure has been identified at this time.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management