
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14618 is a Missing Authorization vulnerability in the Sweet Energy Efficiency plugin for WordPress, affecting all versions up to and including 1.0.6. The flaw allows authenticated attackers with subscriber-level access or above to perform unauthorized read, modification, and deletion of arbitrary energy efficiency graphs via the sweet_energy_efficiency_action AJAX handler. It was published on December 18, 2025, and assigned by Wordfence. The vulnerability carries a CVSS v3.1 base score of 4.3 (Medium) (Wordfence, Red Hat CVE).
The root cause is classified as CWE-862 (Missing Authorization): the sweet_energy_efficiency_action AJAX handler in the Sweet Energy Efficiency WordPress plugin does not perform a capability check before processing requests. This means any authenticated WordPress user — including those with the lowest default role (subscriber) — can invoke the handler to read, modify, or delete graph data that should be restricted to administrators. Exploitation requires only a valid WordPress account on the target site and a crafted AJAX request to the vulnerable endpoint (Wordfence, WordPress Trac).
Successful exploitation allows authenticated low-privileged users to read, alter, or permanently delete energy efficiency graph data managed by the plugin, impacting data integrity and availability of that content. Confidentiality impact is assessed as none, as the primary risk is unauthorized modification and deletion rather than sensitive data disclosure. The scope is limited to the plugin's graph data and does not directly enable system-level compromise or lateral movement (Wordfence).
No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported for CVE-2025-14618. The EPSS score is approximately 0.025% (0.000250), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an authenticated session, further limiting the attack surface (Wordfence).
wp-admin/admin-ajax.php with the action parameter set to sweet_energy_efficiency_action and appropriate parameters to read, modify, or delete a graph (e.g., specifying a graph ID and a delete or update operation).wp-admin/admin-ajax.php with action=sweet_energy_efficiency_action from low-privileged user accounts.sweet_energy_efficiency_action handler from subscriber-level accounts, especially with delete or update operations.Users should update the Sweet Energy Efficiency plugin to version 1.0.7 or later, which introduces the missing capability check on the AJAX handler. Patches are available via the WordPress plugin repository changesets 3417589 and 3420909. As a temporary workaround, site administrators can restrict user registration or remove untrusted subscriber accounts until the update is applied (WordPress Trac, WordPress Trac v2).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."