Junglewise Threat Intelligence

CVE-2026-14925: Import WP missing authorization on export file downloads

CVE-2026-14925 · Severity: high · CVSS 7.5 · Published 2026-08-12

Executive brief

Import WP is a WordPress plugin that helps administrators export user data like email addresses and roles. Before version 2.14.23, the plugin failed to verify user permissions when downloading previously-generated export files, allowing unauthenticated attackers to steal sensitive administrator-exported data if they could guess the time-based download key.

Technical details

The vulnerability is an authorization bypass (CWE-200) in the export file download handler. The plugin uses a low-entropy, time-based MD5 hash as the download key without validating user authentication or authorization. Attackers can enumerate exporter IDs and brute-force the download key (MD5 of the Unix timestamp when the export completed) to retrieve unconsumed export files containing user personal data. The attack is network-accessible and requires no authentication, but presupposes an unconsumed export exists and the attacker can narrow the export timestamp window. The vulnerability was patched in version 2.14.23, which now returns HTTP 403 for requests lacking proper authorization.

Affected products

  • Connekt Import WP before 2.14.23

Timeline

  • 2026-08-10: disclosed
  • 2026-08-10: patched: Fixed in version 2.14.23

References