CVE-2025-14943: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-14943 is a Sensitive Information Exposure vulnerability in the Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress, affecting all versions up to and including 8.7.2. The flaw stems from a misconfigured authorization check in the getShipItemFullText function, which allows any authenticated user with Subscriber-level access or above to access content they should not be permitted to view. It was disclosed on January 10, 2026, with the CVE assigned by Wordfence. The vulnerability carries a CVSS v3.1 base score of 4.3 (Medium) (Wordfence, Feedly).

Technical details

The root cause is classified as CWE-863 (Incorrect Authorization). The getShipItemFullText function in includes/Ajax/Get.php performs an authorization check that only validates whether the requesting user holds the generic WordPress read capability (Subscriber-level) and possesses a valid nonce, but does not verify whether the user is actually authorized to access the specific post being requested. This allows any authenticated low-privilege user to supply an arbitrary post ID and retrieve the full text of password-protected, private, or draft posts via a network-accessible AJAX endpoint, requiring no special configuration or elevated privileges beyond a basic WordPress account (Wordfence, WordPress Trac).

Impact

Successful exploitation allows authenticated attackers with minimal privileges (Subscriber-level) to read the full content of posts that site administrators have intentionally restricted — including password-protected posts, private posts, and unpublished drafts. This can expose sensitive business information, unreleased content, or confidential data stored in draft form. There is no impact on integrity or availability, and the scope is limited to the confidentiality of post content within the affected WordPress installation (Feedly, Wordfence).

Exploitability

No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.025% (0.000250), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a valid authenticated WordPress account at Subscriber level or above, limiting the attack surface to sites with open user registration or where an attacker has already obtained credentials (Feedly, Wordfence).

Exploitation steps

  1. Obtain Subscriber-level access: Register for an account on the target WordPress site (if open registration is enabled) or use existing low-privilege credentials.
  2. Retrieve a valid nonce: Log in and obtain a valid WordPress nonce, which is typically embedded in page source or returned via standard WordPress AJAX nonce endpoints accessible to authenticated users.
  3. Identify target post IDs: Enumerate post IDs by observing publicly visible post IDs on the site, or by iterating through sequential integer IDs.
  4. Send crafted AJAX request: Submit an HTTP POST request to the WordPress AJAX endpoint (e.g., wp-admin/admin-ajax.php) invoking the getShipItemFullText action, supplying the target post ID and the valid nonce.
  5. Extract restricted content: The function returns the full text of the requested post regardless of its visibility status (private, password-protected, or draft), exposing the content to the attacker (Wordfence, WordPress Trac).

Indicators of compromise

  • Network: Unusual or repeated POST requests to wp-admin/admin-ajax.php with an action parameter corresponding to getShipItemFullText from low-privilege user accounts; requests targeting multiple sequential post IDs in a short time window.
  • Logs: WordPress access logs showing authenticated Subscriber-level users making frequent AJAX calls to the Blog2Social endpoint; requests for post IDs that correspond to private, draft, or password-protected posts.
  • Application: Unexpected access patterns in WordPress audit logs where Subscriber-level accounts are associated with retrieval of restricted post content.

Mitigation and workarounds

Site administrators should update the Blog2Social plugin to version 8.7.3 or later, which contains the fix for the improper authorization check in the getShipItemFullText function (Feedly, Wordfence). As an interim measure, sites that do not require open user registration should disable it to reduce the pool of potential attackers. Additionally, reviewing and auditing which users hold Subscriber-level access or above can help limit exposure until the patch is applied.

Community reactions

Sucuri included this vulnerability in their January 2026 vulnerability patch roundup, highlighting it as one of several WordPress plugin issues requiring attention (Sucuri Blog). No significant broader media coverage or notable researcher commentary beyond standard vulnerability disclosure channels has been identified for this CVE.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management