
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14438 is a Server-Side Request Forgery (SSRF) vulnerability in the Xagio SEO – AI Powered SEO plugin for WordPress, affecting all versions up to and including 7.1.0.30. The flaw resides in the pixabayDownloadImage function and allows authenticated attackers with Subscriber-level access or higher to make arbitrary web requests originating from the web server. It was published on January 6, 2026, and assigned a CVSS v3.1 base score of 6.4 (Medium) by Wordfence (Wordfence, NVD).
The vulnerability is classified as CWE-918 (Server-Side Request Forgery) and stems from insufficient validation of user-supplied URLs within the pixabayDownloadImage function of the Xagio SEO plugin. Specifically, the vulnerable code paths are located in inc/xagio_core.php (line 236) and modules/seo/models/xagio_tinymce.php (lines 91 and 135), where attacker-controlled input is passed to server-side HTTP request functions without adequate sanitization or allowlist enforcement. An attacker with at minimum a WordPress Subscriber account can supply an arbitrary URL, causing the server to issue HTTP requests to internal or external destinations, potentially exposing internal services or enabling data modification (Wordfence, Plugin Changeset).
Successful exploitation allows authenticated attackers to pivot the WordPress server as a proxy to reach internal network services that would otherwise be inaccessible from the internet, enabling reconnaissance of internal infrastructure, access to metadata services (e.g., cloud instance metadata endpoints), and potential modification of data in connected internal services. The CVSS scope is marked as "Changed," reflecting that the impact extends beyond the vulnerable component itself. Confidentiality and integrity are both partially compromised, though availability is not directly affected (Wordfence).
No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported for CVE-2025-14438. The EPSS score is approximately 0.028% (0.000280), indicating a very low probability of exploitation in the near term. The vulnerability requires at least Subscriber-level authentication, which limits the attack surface compared to unauthenticated flaws. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Wordfence).
wp-content/plugins/xagio-seo/readme.txt.pixabayDownloadImage function within the plugin.http://169.254.169.254/latest/meta-data/ for AWS metadata, or an internal service address like http://192.168.1.1/admin).wp-admin/admin-ajax.php) with suspicious URL parameters; server-side HTTP client logs showing requests to internal addresses.Users should update the Xagio SEO plugin to a version beyond 7.1.0.30, as the fix was introduced in the subsequent release (changeset 3426300 addresses the vulnerable code paths). The patch can be reviewed at the official WordPress plugin repository changeset. As a temporary workaround, site administrators can restrict Subscriber-level user registration or disable the plugin until an update is applied. Additionally, network-level controls such as egress filtering on the web server to block requests to internal IP ranges can reduce SSRF impact (Plugin Changeset, Wordfence).
The vulnerability was reported and disclosed by Wordfence, which serves as the CNA for this CVE. No notable independent researcher commentary, significant media coverage, or widespread social media discussion has been identified beyond standard vulnerability aggregator postings (Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."