CVE-2025-14574: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-14574 is a Sensitive Information Exposure vulnerability in the weDocs plugin for WordPress, classified under CWE-200. It affects all versions of the plugin up to and including 2.1.15, allowing unauthenticated attackers to extract sensitive data — including third-party service API keys — via the /wp-json/wp/v2/docs/settings REST API endpoint. The vulnerability was published on January 9, 2026, and assigned by Wordfence. It carries a CVSS v3.1 base score of 5.3 (Medium) (Wordfence).

Technical details

The root cause is improper access control on the /wp-json/wp/v2/docs/settings REST API endpoint in the weDocs WordPress plugin (CWE-200: Exposure of Sensitive Information to an Unauthorized Actor). The endpoint does not enforce authentication, meaning any unauthenticated network attacker can send a simple HTTP GET request to retrieve plugin settings that may contain sensitive configuration data, including API keys for third-party services. No special privileges, user interaction, or complex conditions are required for exploitation. The fix was introduced in version 2.1.16, as evidenced by the plugin changeset (WordPress Plugin Changeset, Wordfence).

Impact

Successful exploitation allows unauthenticated remote attackers to read sensitive plugin configuration data, most critically API keys for integrated third-party services. Exposure of these API keys could enable attackers to abuse those services (e.g., sending spam, incurring costs, accessing external data stores), impersonate the site owner in third-party platforms, or use the credentials as a foothold for further attacks. Integrity and availability of the WordPress site itself are not directly impacted by this vulnerability (Wordfence).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-14574. The EPSS score is approximately 0.038%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the trivial nature of exploitation — a single unauthenticated HTTP GET request — means the barrier to abuse is extremely low for any attacker who identifies a vulnerable site (Wordfence).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the weDocs plugin (versions ≤ 2.1.15) using tools like WPScan, Shodan, or by checking /wp-content/plugins/wedocs/ for plugin presence.
  2. Confirm vulnerability: Verify the target is running a vulnerable version by checking the plugin's readme.txt or changelog at /wp-content/plugins/wedocs/readme.txt.
  3. Send unauthenticated request: Issue an HTTP GET request to the target's REST API endpoint:
    GET /wp-json/wp/v2/docs/settings HTTP/1.1
    Host: <target-site>
  4. Extract sensitive data: Parse the JSON response for API keys and other third-party service credentials stored in the plugin's settings.
  5. Abuse extracted credentials: Use the harvested API keys to access or abuse the associated third-party services (e.g., AI chatbot APIs, email services) (Wordfence).

Indicators of compromise

  • Network: Unauthenticated HTTP GET requests to /wp-json/wp/v2/docs/settings from external or unexpected IP addresses in web server access logs.
  • Logs: WordPress access logs showing repeated or automated requests to the docs/settings REST API endpoint, particularly from IPs with no prior site interaction or from known scanning infrastructure.
  • Third-Party Services: Unexpected usage spikes, unauthorized API calls, or billing anomalies in third-party services whose API keys are stored in the weDocs plugin settings.

Mitigation and workarounds

Update the weDocs plugin to version 2.1.16 or later, which patches the unauthenticated access to the sensitive settings endpoint (WordPress Plugin Changeset). As an immediate workaround prior to patching, site administrators should rotate any API keys stored in the weDocs plugin settings and consider temporarily disabling the plugin if it is not critical to operations. Additionally, using a Web Application Firewall (WAF) rule to block unauthenticated access to /wp-json/wp/v2/docs/settings can reduce exposure (Wordfence).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management