CVE-2025-14718: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-14718 is an authorization bypass vulnerability in the Schedule Post Changes With PublishPress Future plugin for WordPress, affecting all versions up to and including 4.9.3. The flaw allows authenticated attackers with Contributor-level access or higher to create, update, delete, and publish malicious workflows that can automatically delete any post upon publication or update — including posts authored by administrators. It was disclosed on January 9, 2026, with the CVE record submitted by Wordfence. The vulnerability carries a CVSS v3.1 base score of 5.4 (Medium) (Wordfence, NVD).

Technical details

The vulnerability is classified as CWE-862 (Missing Authorization), meaning the plugin's REST API endpoint (RestApiV1.php) fails to properly verify whether the requesting user has the necessary permissions to perform workflow management actions. Because authorization checks are absent or insufficient, a low-privileged authenticated user (Contributor and above) can invoke REST API calls to create or manipulate automation workflows — including those configured to delete posts on publication or update events. The patch introduced in version 4.9.4 addresses this by adding proper capability checks in src/Modules/Workflows/Rest/RestApiV1.php (Wordfence, WordPress Trac).

Impact

Successful exploitation allows an authenticated attacker with minimal privileges to manipulate post-lifecycle workflows, resulting in unauthorized deletion of any WordPress post — including content created by administrators. This primarily affects integrity (unauthorized modification/deletion of content) and availability (content destruction), with no direct confidentiality impact. In a multi-author WordPress environment, a malicious contributor could systematically destroy published content site-wide, causing significant operational disruption (Wordfence, NVD).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.036%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a valid authenticated account with at least Contributor-level access, which limits the attack surface compared to unauthenticated vulnerabilities (Wordfence, Feedly).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the PublishPress Future plugin (versions ≤ 4.9.3) by checking plugin metadata via /wp-content/plugins/post-expirator/readme.txt or using tools like WPScan.
  2. Obtain Contributor access: Register or use an existing low-privileged account (Contributor level or above) on the target WordPress site.
  3. Identify the REST API endpoint: Locate the workflow management REST API endpoint exposed by the plugin (e.g., under /wp-json/publishpress-future/v1/workflows/).
  4. Craft a malicious workflow: Send an authenticated REST API request (with a valid WordPress nonce or authentication cookie) to create or update a workflow configured to automatically delete posts upon publication or update.
  5. Trigger the workflow: Publish or update any post on the site to activate the malicious workflow, causing targeted or broad post deletion — including administrator-authored content (Wordfence, WordPress Trac).

Indicators of compromise

  • Logs: WordPress access logs showing unexpected REST API calls to /wp-json/publishpress-future/v1/workflows/ (POST/PUT/DELETE methods) from Contributor-level user accounts; repeated workflow creation or modification events in WordPress debug logs.
  • Database: Unexpected or unfamiliar workflow entries in the WordPress database associated with the PublishPress Future plugin; posts being deleted shortly after publication or update without administrator action.
  • File System: No direct file-system artifacts expected, but review plugin configuration tables (wp_options or custom plugin tables) for unauthorized workflow definitions.
  • Behavior: Unexplained mass deletion of posts, particularly those authored by administrators, coinciding with publication or update events by lower-privileged users.

Mitigation and workarounds

The vendor (PublishPress) released version 4.9.4 of the Schedule Post Changes With PublishPress Future plugin, which adds proper authorization checks to the affected REST API endpoint. Site administrators should update the plugin to version 4.9.4 or later immediately via the WordPress admin dashboard or WP-CLI (wp plugin update post-expirator). As a temporary workaround, administrators can restrict Contributor-level user registration or disable the plugin until the update is applied. Reviewing existing workflows for unauthorized entries is also recommended post-update (Wordfence, WordPress Trac).

Community reactions

Wordfence disclosed the vulnerability and assigned the CVE as the coordinating CNA. Sucuri included it in their January 2026 vulnerability patch roundup, noting it as one of several WordPress plugin issues requiring prompt attention (Sucuri Blog). No significant broader media coverage or notable researcher commentary beyond standard vulnerability disclosure channels has been identified.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management