CVE-2025-14610: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-14610 is a Server-Side Request Forgery (SSRF) vulnerability in the TableMaster for Elementor WordPress plugin, affecting all versions up to and including 1.3.6. The flaw allows authenticated attackers with Author-level access or above to make arbitrary web requests — including to localhost and internal network services — and read sensitive files such as wp-config.php via the csv_url parameter in the Data Table widget. It was published on January 28, 2026, and assigned a CVSS v3.1 base score of 7.2 (High) by Wordfence (Wordfence, Red Hat CVE).

Technical details

The root cause is classified as CWE-918 (Server-Side Request Forgery), arising from the plugin's failure to validate or restrict URLs supplied to the csv_url parameter when importing CSV data in the Data Table widget (Wordfence). An attacker with at least Author-level WordPress credentials can supply an arbitrary URL — including file://, http://localhost/, or internal network addresses — causing the server to fetch and return the content of that resource. The vulnerable code is located in modules/data-table/widgets/data-table.php at line 446 of the plugin (WordPress Trac). No authentication bypass is required; the attacker only needs a valid WordPress account with Author privileges or higher.

Impact

Successful exploitation allows an attacker to read sensitive server-side files — most critically wp-config.php, which contains database credentials and secret keys — and probe internal network services not exposed to the internet. This creates risks of credential theft, database compromise, and potential lateral movement within the hosting environment. Confidentiality and integrity are both impacted (low severity each per CVSS), while availability is unaffected (Wordfence, Red Hat CVE).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported as of the available data. The EPSS score is approximately 0.028% (0.000280), indicating a low probability of near-term exploitation (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, though it was referenced in a CISA vulnerability bulletin for the week of January 26, 2026 (CISA Bulletin). Exploitation requires at minimum Author-level WordPress credentials, which limits the attack surface compared to unauthenticated vulnerabilities.

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the TableMaster for Elementor plugin (version ≤ 1.3.6) using tools like WPScan or by inspecting plugin directories.
  2. Obtain credentials: Acquire or use existing Author-level (or higher) WordPress credentials — e.g., through phishing, credential stuffing, or a compromised account.
  3. Access the Data Table widget: Log in to the WordPress admin panel and navigate to an Elementor page editor containing a Data Table widget, or create a new page with one.
  4. Inject malicious URL: In the CSV import field, supply a crafted value for the csv_url parameter pointing to an internal resource, such as http://localhost/wp-config.php or file:///var/www/html/wp-config.php.
  5. Retrieve sensitive data: Submit the request; the server fetches the specified URL and returns its contents, exposing database credentials, secret keys, or internal service responses to the attacker (Wordfence, WordPress Trac).

Indicators of compromise

  • Logs: WordPress access logs showing POST requests to Elementor AJAX endpoints (e.g., admin-ajax.php or REST API routes) with csv_url parameters containing localhost, 127.0.0.1, file://, or internal IP ranges.
  • Logs: Server-side errors or unusual responses in PHP/web server logs triggered by attempts to fetch local file paths or internal hostnames.
  • Network: Outbound HTTP requests from the web server process to internal network addresses or loopback interfaces that are not typical for normal WordPress operation.
  • File System: No direct file artifacts expected, but review for unauthorized changes to wp-config.php or new admin accounts created after potential credential exposure.

Mitigation and workarounds

Users should update the TableMaster for Elementor plugin to a version beyond 1.3.6, which includes the fix restricting permissible URLs for CSV imports (WordPress Trac Changeset). As a workaround, site administrators should restrict Author-level user permissions and audit which users have content creation roles. Additionally, deploying a Web Application Firewall (WAF) with SSRF detection rules — such as those provided by Wordfence — can help block exploitation attempts (Wordfence).

Community reactions

Wordfence disclosed and assigned this CVE, publishing it in their weekly WordPress vulnerability report for January 26 – February 1, 2026 (Wordfence Blog). The vulnerability was noted in a CISA vulnerability summary bulletin (CISA Bulletin) and received brief social media attention via RedPacketSecurity on Mastodon. No significant broader media coverage or notable researcher commentary beyond standard disclosure channels has been observed.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management