
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14610 is a Server-Side Request Forgery (SSRF) vulnerability in the TableMaster for Elementor WordPress plugin, affecting all versions up to and including 1.3.6. The flaw allows authenticated attackers with Author-level access or above to make arbitrary web requests — including to localhost and internal network services — and read sensitive files such as wp-config.php via the csv_url parameter in the Data Table widget. It was published on January 28, 2026, and assigned a CVSS v3.1 base score of 7.2 (High) by Wordfence (Wordfence, Red Hat CVE).
The root cause is classified as CWE-918 (Server-Side Request Forgery), arising from the plugin's failure to validate or restrict URLs supplied to the csv_url parameter when importing CSV data in the Data Table widget (Wordfence). An attacker with at least Author-level WordPress credentials can supply an arbitrary URL — including file://, http://localhost/, or internal network addresses — causing the server to fetch and return the content of that resource. The vulnerable code is located in modules/data-table/widgets/data-table.php at line 446 of the plugin (WordPress Trac). No authentication bypass is required; the attacker only needs a valid WordPress account with Author privileges or higher.
Successful exploitation allows an attacker to read sensitive server-side files — most critically wp-config.php, which contains database credentials and secret keys — and probe internal network services not exposed to the internet. This creates risks of credential theft, database compromise, and potential lateral movement within the hosting environment. Confidentiality and integrity are both impacted (low severity each per CVSS), while availability is unaffected (Wordfence, Red Hat CVE).
No public exploit code or active in-the-wild exploitation has been reported as of the available data. The EPSS score is approximately 0.028% (0.000280), indicating a low probability of near-term exploitation (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, though it was referenced in a CISA vulnerability bulletin for the week of January 26, 2026 (CISA Bulletin). Exploitation requires at minimum Author-level WordPress credentials, which limits the attack surface compared to unauthenticated vulnerabilities.
csv_url parameter pointing to an internal resource, such as http://localhost/wp-config.php or file:///var/www/html/wp-config.php.admin-ajax.php or REST API routes) with csv_url parameters containing localhost, 127.0.0.1, file://, or internal IP ranges.wp-config.php or new admin accounts created after potential credential exposure.Users should update the TableMaster for Elementor plugin to a version beyond 1.3.6, which includes the fix restricting permissible URLs for CSV imports (WordPress Trac Changeset). As a workaround, site administrators should restrict Author-level user permissions and audit which users have content creation roles. Additionally, deploying a Web Application Firewall (WAF) with SSRF detection rules — such as those provided by Wordfence — can help block exploitation attempts (Wordfence).
Wordfence disclosed and assigned this CVE, publishing it in their weekly WordPress vulnerability report for January 26 – February 1, 2026 (Wordfence Blog). The vulnerability was noted in a CISA vulnerability summary bulletin (CISA Bulletin) and received brief social media attention via RedPacketSecurity on Mastodon. No significant broader media coverage or notable researcher commentary beyond standard disclosure channels has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."