OVERVIEW CVE-2025-14944 is a missing authorization vulnerability in the Backup Migration plugin for WordPress affecting all versions up to and including 2.0.0. The vulnerability exists in the 'initializeOfflineAjax' function, which lacks both proper capability checks and nonce verification. The endpoint relies solely on hardcoded tokens that are publicly exposed in the plugin's JavaScript, allowing unauthenticated attackers to bypass authentication controls. SEVERITY The vulnerability carries a CVSS score of 5.3 (Medium) with a network-based attack vector requiring no user interaction and minimal complexity. The attack surface is broad, as it can be exploited by any unauthenticated internet user without special privileges or user interaction. While the impact does not affect confidentiality or integrity, the availability impact is notable, as successful exploitation enables attackers to trigger backup upload queue processing, potentially causing resource exhaustion and unexpected data transfers to configured cloud storage targets. EXPLOITATION STATUS This vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and remains inactive on vulnerability hotlists, indicating no confirmed active exploitation at this time. The EPSS score of 0.00046 suggests minimal real-world exploitation probability. However, the straightforward nature of the attack—requiring only network access and no special authentication—combined with public exposure of the hardcoded tokens means exploitation code could be developed readily if the vulnerability gains attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Inisev | BackupBliss – Backup & Migration With Free Cloud Storage | >= 0, <= 2.0.0CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.