CVE-2025-14633: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-14633 is a Missing Authorization vulnerability in the F70 Lead Document Download plugin for WordPress that allows unauthenticated attackers to download arbitrary files from the WordPress media library. The flaw affects all versions of the plugin up to and including 1.4.4. It was published on December 20, 2025, and assigned a CVSS v3.1 base score of 5.3 (Medium) (Wordfence, ENISA EUVD).

Technical details

The vulnerability is classified as CWE-862 (Missing Authorization) and stems from the absence of a capability check in the file_download function within includes/class.download.php (line 61). Because no authentication or permission validation is enforced before serving files, any unauthenticated remote attacker can trigger the download endpoint and retrieve media library files by supplying or enumerating WordPress attachment IDs. The attack requires no privileges, no user interaction, and is exploitable over the network with low complexity (Wordfence, WordPress Trac).

Impact

Successful exploitation results in unauthorized disclosure of files stored in the WordPress media library, which may include sensitive lead documents, contracts, internal reports, or other confidential files uploaded by site administrators. The confidentiality impact is rated Low in scope (limited to media library contents), with no integrity or availability impact. However, depending on what documents are stored in the media library, the practical business impact could be significantly higher than the CVSS score suggests (ENISA EUVD, Wordfence).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-14633 as of the available data. The EPSS score is approximately 0.037%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The attack is trivially executable by any unauthenticated user who can enumerate or guess WordPress attachment IDs, which are sequential integers and therefore easily brute-forced (Wordfence, ENISA EUVD).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the F70 Lead Document Download plugin (version ≤ 1.4.4) using tools like WPScan, Shodan, or by checking the plugin's presence via /wp-content/plugins/f70-lead-document-download/.
  2. Enumerate attachment IDs: WordPress attachment IDs are sequential integers. An attacker can enumerate them by iterating over common ID ranges (e.g., 1–10000) or by observing publicly visible attachment URLs on the target site.
  3. Craft download request: Send an unauthenticated HTTP request to the plugin's file_download endpoint with a target attachment ID as a parameter (e.g., GET /?f70_download=<attachment_id> or the equivalent AJAX action), bypassing any authorization check.
  4. Retrieve file: The server responds with the requested media library file, allowing the attacker to download sensitive documents without any authentication (Wordfence, WordPress Trac).

Indicators of compromise

  • Network: Repeated unauthenticated HTTP GET or POST requests to the WordPress site targeting the file_download endpoint or AJAX action associated with the F70 Lead Document Download plugin, particularly with sequentially incrementing attachment ID parameters.
  • Logs: WordPress access logs showing high volumes of requests to the plugin's download handler from a single IP or range of IPs, especially with varying numeric attachment ID values and no associated authenticated session cookies.
  • File System: No direct file system artifacts are expected from read-only exploitation; however, monitor for unexpected access patterns in WordPress media library directories (/wp-content/uploads/).

Mitigation and workarounds

Users should update the F70 Lead Document Download plugin to version 1.4.5 or later, which introduces the missing capability check and resolves the unauthorized access issue. As an interim workaround, site administrators can deactivate or remove the plugin until the update can be applied. Additionally, restricting access to the WordPress media library via server-level controls (e.g., .htaccess rules or web application firewall rules) can reduce exposure (Wordfence, ENISA EUVD).

Community reactions

The vulnerability was discovered and reported by Wordfence, which published the advisory and assigned the CVE. Coverage has been limited to automated vulnerability aggregators and security feeds, with no notable researcher commentary or significant social media discussion beyond standard CVE broadcast posts (Wordfence).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management