๐Ÿ” CVE Alert

CVE-2026-14925

UNKNOWN 0.0

Import WP < 2.14.23 - Unauthenticated Sensitive Information Exposure via Export File Download

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Import WP WordPress plugin before 2.14.23 does not perform any authorization check on one of its export-file download handlers, allowing unauthenticated attackers to download export files generated by administrators, which may contain user personal data such as email addresses, login names and roles. Exploitation requires an unconsumed export to already exist and a low-entropy, time-based download key to be obtained.

Vendor unknown
Product import wp
Published Aug 12, 2026
Stay Ahead of the Next One

Get instant alerts for unknown import wp

Be the first to know when new unknown vulnerabilities affecting unknown import wp are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Import WP
0 < 2.14.23

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/67be2cc3-06d3-419e-8ca4-6dad442a02ca/

Credits

Muni Nitish Kumar Yaddala WPScan