CVE-2025-14360
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-14360 is a Missing Authorization (Broken Access Control) vulnerability in the Kaira Blockons WordPress plugin that allows unauthenticated attackers to access functionality not properly constrained by ACLs. It affects Blockons versions up to and including 1.2.19 (initially disclosed as affecting through 1.2.15, later updated to 1.2.19 in April 2026). The vulnerability was reported by MD ISMAIL on August 13, 2025, and published by Patchstack on January 8, 2026. It carries a CVSS v3.1 base score of 7.5 (High), assigned by Patchstack (Patchstack).

Technical details

The vulnerability is classified as CWE-862 (Missing Authorization), meaning the plugin fails to perform adequate authorization checks — such as capability checks or nonce token validation — before executing privileged functionality. This allows an unauthenticated network attacker to invoke restricted plugin functions directly, bypassing WordPress access control mechanisms. The attack requires no user interaction, no special privileges, and low complexity, making it trivially exploitable over the network (Patchstack).

Impact

Successful exploitation allows an unauthenticated attacker to access sensitive plugin functionality that should be restricted to privileged users. The primary impact is a high confidentiality risk (C:H), with the Patchstack-assigned CVSS vector indicating no direct integrity or availability impact. However, depending on the specific unprotected functionality exposed, attackers could potentially read sensitive configuration data or site information, and Patchstack notes this class of vulnerability is commonly used in mass-exploit campaigns targeting thousands of WordPress sites regardless of their size or popularity (Patchstack).

Exploitability

No public proof-of-concept exploit code has been identified, and there is no confirmed evidence of active in-the-wild exploitation at this time. The EPSS score is approximately 0.017%, indicating a low current probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack classifies it as high priority and notes that broken access control vulnerabilities of this type are frequently leveraged in mass-exploit campaigns against WordPress plugins (Patchstack).

Mitigation and workarounds

As of the time of publication, no official patch from the plugin developer (Kaira) is available for the Blockons plugin. Patchstack has issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts until an official fix is released. Site administrators should consider deactivating and removing the Blockons plugin until a patched version (above 1.2.19) becomes available, or deploy a web application firewall solution such as Patchstack to mitigate the risk (Patchstack).

Community reactions

The vulnerability received brief coverage on security-focused social media accounts, including mentions on Mastodon via TheHackerWire shortly after disclosure in January 2026. No significant vendor statements or notable researcher commentary beyond the Patchstack advisory have been identified.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-13784CRITICAL9.8
  • arforms-form-builder
NoYesAug 16, 2026
CVE-2026-17087HIGH7.5
  • wp-travel-engine
NoYesAug 16, 2026
CVE-2026-2497HIGH7.2
  • gallery-plugin
NoYesAug 16, 2026
CVE-2026-17608MEDIUM6.5
  • wp-compress-image-optimizer
NoYesAug 16, 2026
CVE-2026-2357MEDIUM6.4
  • bold-page-builder
NoYesAug 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management