CVE-2025-14172

T

he WP Page Permalink Extension plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.5.4. This is due to missing authorization checks on the `cwpp_trigger_flush_rewrite_rules` function hooked to `wp_ajax_cwpp_trigger_flush_rewrite_rules`. This makes it possible for authenticated attackers, with Subscriber-level access and above, to flush the site's rewrite rules via the `action` parameter.

Configurations

No configuration.

History

09 Jan 2026, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-09 12:15

Updated : 2026-01-13 14:03


NVD link : CVE-2025-14172

Mitre link : CVE-2025-14172

CVE.ORG link : CVE-2025-14172


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization