Exploitation Summary
EIP tracks 1 public exploit for CVE-2025-14172. PoCs published by RootHarpy.
AI-analyzed exploit summary This repository contains a Nuclei template designed to detect CVE-2025-14172, a missing authorization vulnerability in the WP Page Permalink Extension WordPress plugin. The template sends an authenticated request to `admin-ajax.php` to check for the presence of the vulnerability.
Description
The WP Page Permalink Extension plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.5.4. This is due to missing authorization checks on the `cwpp_trigger_flush_rewrite_rules` function hooked to `wp_ajax_cwpp_trigger_flush_rewrite_rules`. This makes it possible for authenticated attackers, with Subscriber-level access and above, to flush the site's rewrite rules via the `action` parameter.
Exploits (1)
This repository contains a Nuclei template designed to detect CVE-2025-14172, a missing authorization vulnerability in the WP Page Permalink Extension WordPress plugin. The template sends an authenticated request to `admin-ajax.php` to check for the presence of the vulnerability.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L