CVE-2025-14627
Last modified
CVE-2025-14627 is a medium-severity vulnerability rated 6.4/10 on the CVSS scale. The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.35. This is due to inadequate validation of the resolved URL after following Bitly shortlink redirects in the `upload_function()` method. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.35. This is due to inadequate validation of the resolved URL after following Bitly shortlink redirects in the `upload_function()` method. While the initial URL is validated using `wp_http_validate_url()`, when a Bitly shortlink is detected, the `unshorten_bitly_url()` function follows redirects to the final destination URL without re-validating it. This makes it possible for authenticated attackers with Contributor-level access or higher to make the server perform HTTP requests to arbitrary internal endpoints, including localhost, private IP ranges, and cloud metadata services (e.g., 169.254.169.254), potentially exposing sensitive internal data.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-14627?
How severe is CVE-2025-14627?
How do I fix CVE-2025-14627?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-14620A vulnerability was determined in code-projects Student File…9.8
- CVE-2025-14621A vulnerability was identified in code-projects Student File…9.8
- CVE-2025-14622A security flaw has been discovered in code-projects Student…9.8
- CVE-2025-14623A weakness has been identified in code-projects Student File…9.8
- CVE-2025-14625Uncontrolled Search Path Element vulnerability in Altera Qua…6.7
- CVE-2025-14626The QR Code for WooCommerce order emails, PDF invoices, pack…6.4
- CVE-2025-14629The Alchemist Ajax Upload plugin for WordPress is vulnerable…5.3
- CVE-2025-1463The Spreadsheet Integration plugin for WordPress is vulnerab…4.3
- CVE-2025-14630The AdminQuickbar plugin for WordPress is vulnerable to Cros…4.3
- CVE-2025-14631A NULL Pointer Dereference vulnerability in TP-Link Archer B…6.5
- CVE-2025-14632The Filr – Secure document library plugin for WordPress is v…4.4
- CVE-2025-14633The F70 Lead Document Download plugin for WordPress is vulne…5.3
Are you affected by CVE-2025-14627?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
