nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-14895 CVE-2025-14895
MEDIUM
PopupKit <= 2.2.0 - Missing Authorization to Sensitive Information Disclosure and Data Deletion
Record summary
CVE-2025-14895 has a selected CVSS score of 5.4 (medium).
Description
The PopupKit plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.0. This is due to the plugin not properly verifying that a user is authorized to access the /popup/logs REST API endpoint. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read and delete analytics data including device types, browser information, countries, referrer URLs, and campaign metrics.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 10, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce TriggersBrowse roxnor / Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce TriggersDefault status: unaffected | CVE List | Through 2.2.0 | affected |
References
5plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/browser/popup-builder-block/tags/2.2.0/includes/Routes/Popup.php plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/changeset/3421671/popup-builder-block/trunk/includes/Routes/Popup.php research.cleantalk.org
https://research.cleantalk.org/cve-2025-14895 wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/c13bb699-f065-4065-9ea5-bb86d24e09ab?source=cve