
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14574 is a Sensitive Information Exposure vulnerability in the weDocs plugin for WordPress, classified under CWE-200. It affects all versions of the plugin up to and including 2.1.15, allowing unauthenticated attackers to extract sensitive data — including third-party service API keys — via the /wp-json/wp/v2/docs/settings REST API endpoint. The vulnerability was published on January 9, 2026, and assigned by Wordfence. It carries a CVSS v3.1 base score of 5.3 (Medium) (Wordfence).
The root cause is improper access control on the /wp-json/wp/v2/docs/settings REST API endpoint in the weDocs WordPress plugin (CWE-200: Exposure of Sensitive Information to an Unauthorized Actor). The endpoint does not enforce authentication, meaning any unauthenticated network attacker can send a simple HTTP GET request to retrieve plugin settings that may contain sensitive configuration data, including API keys for third-party services. No special privileges, user interaction, or complex conditions are required for exploitation. The fix was introduced in version 2.1.16, as evidenced by the plugin changeset (WordPress Plugin Changeset, Wordfence).
Successful exploitation allows unauthenticated remote attackers to read sensitive plugin configuration data, most critically API keys for integrated third-party services. Exposure of these API keys could enable attackers to abuse those services (e.g., sending spam, incurring costs, accessing external data stores), impersonate the site owner in third-party platforms, or use the credentials as a foothold for further attacks. Integrity and availability of the WordPress site itself are not directly impacted by this vulnerability (Wordfence).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-14574. The EPSS score is approximately 0.038%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the trivial nature of exploitation — a single unauthenticated HTTP GET request — means the barrier to abuse is extremely low for any attacker who identifies a vulnerable site (Wordfence).
/wp-content/plugins/wedocs/ for plugin presence.readme.txt or changelog at /wp-content/plugins/wedocs/readme.txt.GET /wp-json/wp/v2/docs/settings HTTP/1.1
Host: <target-site>/wp-json/wp/v2/docs/settings from external or unexpected IP addresses in web server access logs.docs/settings REST API endpoint, particularly from IPs with no prior site interaction or from known scanning infrastructure.Update the weDocs plugin to version 2.1.16 or later, which patches the unauthenticated access to the sensitive settings endpoint (WordPress Plugin Changeset). As an immediate workaround prior to patching, site administrators should rotate any API keys stored in the weDocs plugin settings and consider temporarily disabling the plugin if it is not critical to operations. Additionally, using a Web Application Firewall (WAF) rule to block unauthenticated access to /wp-json/wp/v2/docs/settings can reduce exposure (Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."