CVE-2026-14925
Import WP < 2.14.23 - Unauthenticated Sensitive Information Exposure via Export File Download
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Import WP WordPress plugin before 2.14.23 does not perform any authorization check on one of its export-file download handlers, allowing unauthenticated attackers to download export files generated by administrators, which may contain user personal data such as email addresses, login names and roles. Exploitation requires an unconsumed export to already exist and a low-entropy, time-based download key to be obtained.
| Vendor | unknown |
| Product | import wp |
| Published | Aug 12, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown import wp
Be the first to know when new unknown vulnerabilities affecting unknown import wp are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Import WP
0 < 2.14.23
References
Credits
Muni Nitish Kumar Yaddala WPScan