
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14943 is a Sensitive Information Exposure vulnerability in the Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress, affecting all versions up to and including 8.7.2. The flaw stems from a misconfigured authorization check in the getShipItemFullText function, which allows any authenticated user with Subscriber-level access or above to access content they should not be permitted to view. It was disclosed on January 10, 2026, with the CVE assigned by Wordfence. The vulnerability carries a CVSS v3.1 base score of 4.3 (Medium) (Wordfence, Feedly).
The root cause is classified as CWE-863 (Incorrect Authorization). The getShipItemFullText function in includes/Ajax/Get.php performs an authorization check that only validates whether the requesting user holds the generic WordPress read capability (Subscriber-level) and possesses a valid nonce, but does not verify whether the user is actually authorized to access the specific post being requested. This allows any authenticated low-privilege user to supply an arbitrary post ID and retrieve the full text of password-protected, private, or draft posts via a network-accessible AJAX endpoint, requiring no special configuration or elevated privileges beyond a basic WordPress account (Wordfence, WordPress Trac).
Successful exploitation allows authenticated attackers with minimal privileges (Subscriber-level) to read the full content of posts that site administrators have intentionally restricted — including password-protected posts, private posts, and unpublished drafts. This can expose sensitive business information, unreleased content, or confidential data stored in draft form. There is no impact on integrity or availability, and the scope is limited to the confidentiality of post content within the affected WordPress installation (Feedly, Wordfence).
No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.025% (0.000250), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a valid authenticated WordPress account at Subscriber level or above, limiting the attack surface to sites with open user registration or where an attacker has already obtained credentials (Feedly, Wordfence).
wp-admin/admin-ajax.php) invoking the getShipItemFullText action, supplying the target post ID and the valid nonce.wp-admin/admin-ajax.php with an action parameter corresponding to getShipItemFullText from low-privilege user accounts; requests targeting multiple sequential post IDs in a short time window.Site administrators should update the Blog2Social plugin to version 8.7.3 or later, which contains the fix for the improper authorization check in the getShipItemFullText function (Feedly, Wordfence). As an interim measure, sites that do not require open user registration should disable it to reduce the pool of potential attackers. Additionally, reviewing and auditing which users hold Subscriber-level access or above can help limit exposure until the patch is applied.
Sucuri included this vulnerability in their January 2026 vulnerability patch roundup, highlighting it as one of several WordPress plugin issues requiring attention (Sucuri Blog). No significant broader media coverage or notable researcher commentary beyond standard vulnerability disclosure channels has been identified for this CVE.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."