Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-14944

20
FAUCET Score

OVERVIEW CVE-2025-14944 is a missing authorization vulnerability in the Backup Migration plugin for WordPress affecting all versions up to and including 2.0.0. The vulnerability exists in the 'initializeOfflineAjax' function, which lacks both proper capability checks and nonce verification. The endpoint relies solely on hardcoded tokens that are publicly exposed in the plugin's JavaScript, allowing unauthenticated attackers to bypass authentication controls. SEVERITY The vulnerability carries a CVSS score of 5.3 (Medium) with a network-based attack vector requiring no user interaction and minimal complexity. The attack surface is broad, as it can be exploited by any unauthenticated internet user without special privileges or user interaction. While the impact does not affect confidentiality or integrity, the availability impact is notable, as successful exploitation enables attackers to trigger backup upload queue processing, potentially causing resource exhaustion and unexpected data transfers to configured cloud storage targets. EXPLOITATION STATUS This vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and remains inactive on vulnerability hotlists, indicating no confirmed active exploitation at this time. The EPSS score of 0.00046 suggests minimal real-world exploitation probability. However, the straightforward nature of the attack—requiring only network access and no special authentication—combined with public exposure of the hardcoded tokens means exploitation code could be developed readily if the vulnerability gains attention.

Impacted Technologies

VendorProductVersion(s)CPE
InisevBackupBliss – Backup & Migration With Free Cloud Storage
>= 0, <= 2.0.0CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 3.1

5.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
LOW
Exploitability Score
3.9
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.56%
Probability of exploitation in next 30 days
EPSS Percentile
43.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0056 is in the 27th percentile among its peer group of 23,723 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

plugins.trac.wordpress.org / browser/backup-backup/trunk/includes/ajax_offline.php
plugins.trac.wordpress.org / browser/backup-backup/trunk/includes/offline.php
plugins.trac.wordpress.org / changeset
wordfence.com / threat-intel/vulnerabilities/id/a2a41a15-0743-48cc-8c92-7cb839fa5847