
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14853 is a Cross-Site Request Forgery (CSRF) vulnerability in the LEAV Last Email Address Validator plugin for WordPress. It affects plugin versions up to and including 1.7.1, and stems from missing or incorrect nonce validation on the display_settings_page function. The vulnerability was published on January 16, 2026, and carries a CVSS v3.1 base score of 4.3 (Medium) (Red Hat CVE, Wordfence).
The root cause is classified as CWE-352 (Cross-Site Request Forgery), arising from the absence of proper nonce validation in the display_settings_page function of the plugin. An unauthenticated attacker can craft a malicious HTTP request that, when triggered by a logged-in administrator (e.g., via a deceptive link or embedded form), causes the administrator's browser to submit unauthorized changes to the plugin's settings. The vulnerable code paths are visible in the plugin's source at leav-settings-page.inc.php (Wordfence, WordPress Trac).
Successful exploitation allows an unauthenticated attacker to modify the LEAV plugin's settings on a vulnerable WordPress site, potentially undermining email validation logic used during user registration or form submissions. The integrity impact is low and scoped to the plugin's configuration; there is no direct confidentiality or availability impact. However, manipulated email validation settings could be leveraged to bypass email verification controls, enabling spam registrations or weakening site security posture (Red Hat CVE, Wordfence).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-14853. The EPSS score is approximately 0.012%, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires social engineering to trick a site administrator into interacting with a malicious link or page (Wordfence).
wp-admin/options-general.php?page=leav-settings), with attacker-controlled parameter values.wp-admin/options-general.php?page=leav-settings from unusual referrers or at unusual times.wp_options table related to the leav plugin settings.Users should upgrade the LEAV Last Email Address Validator plugin to version 1.7.2 or later, which addresses the missing nonce validation. As a general workaround prior to patching, administrators can restrict access to the WordPress admin panel by IP address or require multi-factor authentication to reduce the risk of CSRF exploitation. No additional configuration-based workarounds specific to this vulnerability have been published (Wordfence).
The vulnerability received routine coverage from automated vulnerability tracking services and security aggregators shortly after disclosure. Wordfence documented the issue in their threat intelligence database, and it was noted on Bluesky via automated CVE feeds. No notable researcher commentary or significant media coverage has been identified beyond standard vulnerability database entries (Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."