
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14633 is a Missing Authorization vulnerability in the F70 Lead Document Download plugin for WordPress that allows unauthenticated attackers to download arbitrary files from the WordPress media library. The flaw affects all versions of the plugin up to and including 1.4.4. It was published on December 20, 2025, and assigned a CVSS v3.1 base score of 5.3 (Medium) (Wordfence, ENISA EUVD).
The vulnerability is classified as CWE-862 (Missing Authorization) and stems from the absence of a capability check in the file_download function within includes/class.download.php (line 61). Because no authentication or permission validation is enforced before serving files, any unauthenticated remote attacker can trigger the download endpoint and retrieve media library files by supplying or enumerating WordPress attachment IDs. The attack requires no privileges, no user interaction, and is exploitable over the network with low complexity (Wordfence, WordPress Trac).
Successful exploitation results in unauthorized disclosure of files stored in the WordPress media library, which may include sensitive lead documents, contracts, internal reports, or other confidential files uploaded by site administrators. The confidentiality impact is rated Low in scope (limited to media library contents), with no integrity or availability impact. However, depending on what documents are stored in the media library, the practical business impact could be significantly higher than the CVSS score suggests (ENISA EUVD, Wordfence).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-14633 as of the available data. The EPSS score is approximately 0.037%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The attack is trivially executable by any unauthenticated user who can enumerate or guess WordPress attachment IDs, which are sequential integers and therefore easily brute-forced (Wordfence, ENISA EUVD).
/wp-content/plugins/f70-lead-document-download/.file_download endpoint with a target attachment ID as a parameter (e.g., GET /?f70_download=<attachment_id> or the equivalent AJAX action), bypassing any authorization check.file_download endpoint or AJAX action associated with the F70 Lead Document Download plugin, particularly with sequentially incrementing attachment ID parameters./wp-content/uploads/).Users should update the F70 Lead Document Download plugin to version 1.4.5 or later, which introduces the missing capability check and resolves the unauthorized access issue. As an interim workaround, site administrators can deactivate or remove the plugin until the update can be applied. Additionally, restricting access to the WordPress media library via server-level controls (e.g., .htaccess rules or web application firewall rules) can reduce exposure (Wordfence, ENISA EUVD).
The vulnerability was discovered and reported by Wordfence, which published the advisory and assigned the CVE. Coverage has been limited to automated vulnerability aggregators and security feeds, with no notable researcher commentary or significant social media discussion beyond standard CVE broadcast posts (Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."