Sceawere

Vulnerability Detail

CVE-2026-14925UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Import WP Unauthenticated File Download

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
16h ago
Vendor
Unknown
Product
Import WP
Attack Type
CWE-200 Information Exposure
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Import WP WordPress plugin before 2.14.23 does not perform any authorization check on one of its export-file download handlers, allowing unauthenticated attackers to download export files generated by administrators, which may contain user personal data such as email addresses, login names and roles. Exploitation requires an unconsumed export to already exist and a low-entropy, time-based download key to be obtained.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-08-12T06:17:54.353Z",
  "pubdate": "2026-08-12T06:17:54.353Z",
  "executiveSummary": "An unauthenticated arbitrary file download vulnerability exists in the Import WP WordPress plugin prior to version 2.14.23.\nThe flaw allows remote, unauthenticated attackers to download export files generated by administrators through an export-file download handler that fails to perform requisite authorization checks.\nThe impact includes the exposure of sensitive user personal data, notably email addresses, login names, and user roles.\nThe affected product is the Import WP plugin for WordPress.\nRisk implications are moderate to high depending on the sensitivity of the exported data exposed via the insecure handler.\nAttacker capabilities are limited to downloading existing export files without requiring authentication.\nExploitation requirements dictate that an unconsumed export must already exist on the server, and the attacker must obtain a low-entropy, time-based download key associated with that export.",
  "technicalDetails": "The root cause of the vulnerability lies in the complete absence of authorization checks within a specific export-file download handler implemented by the Import WP plugin.\nThe vulnerable component is the download handler responsible for serving previously generated export files to users.\nAffected versions include all iterations of the Import WP plugin prior to version 2.14.23.\nAuthentication requirements are nonexistent, allowing unauthenticated threat actors to interact with the vulnerable endpoint over the network.\nPrivilege requirements are absent; no valid user session or administrative role is required to trigger the vulnerable functionality.\nNetwork exposure is fully external via standard HTTP/HTTPS protocols exposed by the WordPress installation.\nThe exploitation method relies on interacting with the insecure download handler while supplying a valid download key.\nThe attack flow proceeds as follows: First, the attacker identifies or waits for an administrator to generate an export file that remains unconsumed on the server. Second, the attacker obtains the low-entropy, time-based download key required to access the target file. Third, the attacker issues a direct HTTP request to the vulnerable export-file download handler using the acquired time-based key. Finally, the server processes the request without validating the requester's identity or authorization level, returning the sensitive export file containing user personal data.\nPayload behavior involves referencing the predictable or leaked download key rather than executing arbitrary code.\nPost-exploitation impact is characterized by the unauthorized retrieval of sensitive information, including user personal data such as email addresses, login names, and assigned user roles, which can be leveraged for subsequent attacks such as credential stuffing, phishing, or targeted privilege escalation."
}
CVE-2026-14925: Import WP Unauthenticated File Download (HIGH Severity, CVSS: 7.5) - Sceawere