
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14718 is an authorization bypass vulnerability in the Schedule Post Changes With PublishPress Future plugin for WordPress, affecting all versions up to and including 4.9.3. The flaw allows authenticated attackers with Contributor-level access or higher to create, update, delete, and publish malicious workflows that can automatically delete any post upon publication or update — including posts authored by administrators. It was disclosed on January 9, 2026, with the CVE record submitted by Wordfence. The vulnerability carries a CVSS v3.1 base score of 5.4 (Medium) (Wordfence, NVD).
The vulnerability is classified as CWE-862 (Missing Authorization), meaning the plugin's REST API endpoint (RestApiV1.php) fails to properly verify whether the requesting user has the necessary permissions to perform workflow management actions. Because authorization checks are absent or insufficient, a low-privileged authenticated user (Contributor and above) can invoke REST API calls to create or manipulate automation workflows — including those configured to delete posts on publication or update events. The patch introduced in version 4.9.4 addresses this by adding proper capability checks in src/Modules/Workflows/Rest/RestApiV1.php (Wordfence, WordPress Trac).
Successful exploitation allows an authenticated attacker with minimal privileges to manipulate post-lifecycle workflows, resulting in unauthorized deletion of any WordPress post — including content created by administrators. This primarily affects integrity (unauthorized modification/deletion of content) and availability (content destruction), with no direct confidentiality impact. In a multi-author WordPress environment, a malicious contributor could systematically destroy published content site-wide, causing significant operational disruption (Wordfence, NVD).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.036%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a valid authenticated account with at least Contributor-level access, which limits the attack surface compared to unauthenticated vulnerabilities (Wordfence, Feedly).
/wp-content/plugins/post-expirator/readme.txt or using tools like WPScan./wp-json/publishpress-future/v1/workflows/)./wp-json/publishpress-future/v1/workflows/ (POST/PUT/DELETE methods) from Contributor-level user accounts; repeated workflow creation or modification events in WordPress debug logs.wp_options or custom plugin tables) for unauthorized workflow definitions.The vendor (PublishPress) released version 4.9.4 of the Schedule Post Changes With PublishPress Future plugin, which adds proper authorization checks to the affected REST API endpoint. Site administrators should update the plugin to version 4.9.4 or later immediately via the WordPress admin dashboard or WP-CLI (wp plugin update post-expirator). As a temporary workaround, administrators can restrict Contributor-level user registration or disable the plugin until the update is applied. Reviewing existing workflows for unauthorized entries is also recommended post-update (Wordfence, WordPress Trac).
Wordfence disclosed the vulnerability and assigned the CVE as the coordinating CNA. Sucuri included it in their January 2026 vulnerability patch roundup, noting it as one of several WordPress plugin issues requiring prompt attention (Sucuri Blog). No significant broader media coverage or notable researcher commentary beyond standard vulnerability disclosure channels has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."