CVE-2025-14446
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-14446 is a missing authorization vulnerability in the Popup Builder (Easy Notify Lite) plugin for WordPress, developed by GhozyLab. The flaw allows authenticated attackers with Subscriber-level access or above to reset plugin settings to their default values by exploiting a missing capability check on the easynotify_cp_reset() function. All versions up to and including 1.1.37 are affected. It was published on December 13, 2025, with a CVSS v3.1 base score of 5.4 (Medium) (Red Hat CVE, Wordfence).

Technical details

The root cause is CWE-862 (Missing Authorization) — the easynotify_cp_reset() function in the plugin's enoty-functions.php file does not perform a capability check before executing a settings reset operation. Any authenticated WordPress user, including those with the lowest default role (Subscriber), can invoke this function via a crafted request, bypassing intended administrative controls. The vulnerable code is publicly visible in the plugin's source repository (WordPress Trac, Wordfence).

Impact

Successful exploitation allows an authenticated attacker to reset the Popup Builder plugin's configuration to default values without authorization, resulting in low integrity and low availability impact. This could disrupt popup campaigns, notification settings, or other plugin-managed content, potentially affecting site functionality and user experience. There is no confidentiality impact, and the scope is limited to the affected WordPress installation (Red Hat CVE, Wordfence).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Easy Notify Lite (Popup Builder) plugin version ≤1.1.37 using tools like WPScan or by inspecting publicly accessible plugin metadata.
  2. Obtain low-privilege access: Register or obtain credentials for a Subscriber-level (or higher) WordPress account on the target site.
  3. Craft the reset request: Send an authenticated HTTP POST or GET request to the WordPress admin AJAX endpoint (or the relevant plugin action) that triggers the easynotify_cp_reset() function, without requiring any additional capability or nonce validation.
  4. Achieve unauthorized settings reset: The plugin settings are reset to their default values, disrupting any configured popup or notification campaigns on the target site (Wordfence, WordPress Trac).

Indicators of compromise

  • Logs: WordPress access logs showing authenticated POST requests to wp-admin/admin-ajax.php or plugin-specific endpoints invoking easynotify_cp_reset from low-privilege user accounts.
  • Application: Unexpected reset of Easy Notify Lite plugin settings to defaults, particularly if no administrator performed such an action.
  • User Activity: Subscriber or low-privilege user accounts making repeated or unusual requests to plugin admin functions in WordPress audit logs.

Mitigation and workarounds

Users should update the Easy Notify Lite (Popup Builder) plugin to a version beyond 1.1.37 that includes a proper capability check on the easynotify_cp_reset() function. As a workaround, site administrators can restrict user registration or limit Subscriber-level account creation to trusted users until a patched version is available. Monitoring WordPress audit logs for unauthorized plugin reset actions is also recommended (Wordfence).

Community reactions

Wordfence disclosed the vulnerability as part of their weekly WordPress vulnerability report for December 8–14, 2025, noting it as a missing authorization issue affecting the Easy Notify Lite plugin (Wordfence Blog). No significant broader media coverage or notable researcher commentary beyond standard vulnerability database entries has been observed.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-15991HIGH8.8
  • file-manager
NoYesAug 06, 2026
CVE-2026-15459HIGH8.1
  • wpmudev-updates
NoYesAug 06, 2026
CVE-2026-7529HIGH7.5
  • wisecampaign
NoYesAug 05, 2026
CVE-2026-18325HIGH7.2
  • forminator
NoYesAug 06, 2026
CVE-2026-16636HIGH7.2
  • fluent-smtp
NoYesAug 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management