CVE-2025-12014: NGINX Cache Optimizer <= 1.1 - Missing Authorization to Authenticated (Subscriber+) Dynamic Caching Exclusion Update
The NGINX Cache Optimizer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'nginxcacheoptimizer-blacklist-update' AJAX action in all versions up to, and including, 1.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to add URLs to the Exclude URLs From Dynamic Caching setting.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12014?
CVE-2025-12014 has been classified as a high-severity vulnerability due to its potential for unauthorized data modification.
How do I fix CVE-2025-12014?
To resolve CVE-2025-12014, update the NGINX Cache Optimizer plugin to the latest version beyond 1.1.
Who is affected by CVE-2025-12014?
All users of the NGINX Cache Optimizer plugin for WordPress versions up to and including 1.1 are affected by CVE-2025-12014.
What type of attack does CVE-2025-12014 facilitate?
CVE-2025-12014 facilitates unauthorized modification of data by authenticated attackers exploiting the missing capability check.
Is authentication required for exploiting CVE-2025-12014?
Yes, CVE-2025-12014 requires authentication, allowing attackers with valid credentials to exploit the vulnerability.