CVE-2025-8423 Overview
CVE-2025-8423 affects the My WP Translate plugin for WordPress in all versions up to and including 1.1. The plugin exposes two AJAX handlers, mtswpt_remove_plugin() and ajax_update_export_code(), without proper capability checks. Authenticated users with Subscriber-level access or higher can read and delete arbitrary WordPress options. Deleting core options can break site functionality and trigger a denial of service condition. The weakness is classified as Missing Authorization [CWE-862].
Critical Impact
Any authenticated subscriber can delete arbitrary WordPress options, corrupting site configuration and causing denial of service on affected installations.
Affected Products
- My WP Translate WordPress plugin, versions up to and including 1.1
- WordPress sites that permit user registration at Subscriber level or above
- Any site running the vulnerable class-my-wp-translate-admin.php handlers
Discovery Timeline
- 2025-09-11 - CVE-2025-8423 published to the National Vulnerability Database
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-8423
Vulnerability Analysis
The My WP Translate plugin registers AJAX endpoints backed by the mtswpt_remove_plugin() and ajax_update_export_code() functions. Both handlers execute privileged actions against the WordPress options table without invoking current_user_can() or an equivalent capability check. Any authenticated session, including one belonging to a Subscriber, can invoke these endpoints through the standard admin-ajax.php interface.
The result is unauthorized modification of data. Attackers can enumerate and remove arbitrary entries in wp_options, including values that WordPress and other plugins rely on for basic operation. Removing entries such as siteurl, home, template, or active_plugins breaks the site frontend and dashboard. The vulnerability does not expose data confidentiality directly, but destructive writes translate into a persistent denial of service.
Root Cause
The root cause is a missing authorization check in the affected AJAX callbacks. The handlers rely solely on the presence of an authenticated session and, in some flows, a nonce that Subscribers can obtain. They never verify that the caller holds an administrative capability such as manage_options. This design flaw maps to CWE-862: Missing Authorization.
Attack Vector
Exploitation requires network access to the WordPress site and an authenticated account with Subscriber privileges or higher. On sites that allow open registration, attackers can create their own accounts. Once authenticated, the attacker issues crafted POST requests to admin-ajax.php targeting the vulnerable actions and supplies the name of an option to read or delete. The affected code paths are documented in the plugin source referenced by WordPress Plugin Code Line 1048 and WordPress Plugin Code Line 1130. No user interaction beyond the attacker's own request is required.
See the Wordfence Vulnerability Report for additional technical details.
Detection Methods for CVE-2025-8423
Indicators of Compromise
- Unexpected admin-ajax.php POST requests with action=mtswpt_remove_plugin or action=ajax_update_export_code originating from low-privilege accounts.
- Missing or reset entries in wp_options, including core keys such as siteurl, home, template, or active_plugins.
- WordPress error logs referencing failed option lookups or fatal errors immediately after Subscriber-authenticated requests.
- Sudden site outages or white-screen errors correlated with recent low-privilege user activity.
Detection Strategies
- Enable HTTP request logging on the web server and alert on admin-ajax.php calls invoking the two vulnerable actions.
- Correlate the authenticated user role in wp_users with the actions submitted to admin-ajax.php and flag Subscriber-level access to admin-only endpoints.
- Use file integrity and database change monitoring to detect deletions in wp_options.
Monitoring Recommendations
- Baseline the current contents of wp_options and alert on delete operations affecting protected keys.
- Monitor new user registrations followed by immediate AJAX activity to plugin-specific actions.
- Forward WordPress and web server logs to a centralized analytics platform for retention and correlation.
How to Mitigate CVE-2025-8423
Immediate Actions Required
- Deactivate and remove the My WP Translate plugin on all sites running version 1.1 or earlier until a patched release is verified.
- Audit wp_options for missing or altered entries and restore from a known-good backup if tampering is confirmed.
- Disable open user registration or restrict the default new user role to prevent trivial acquisition of Subscriber access.
- Rotate credentials for any low-privilege accounts that show suspicious AJAX activity.
Patch Information
No fixed version is identified in the referenced advisories at the time of publication. Monitor the Wordfence Vulnerability Report and the plugin listing for an update beyond version 1.1, and apply it as soon as it becomes available.
Workarounds
- Block requests to admin-ajax.php with action=mtswpt_remove_plugin or action=ajax_update_export_code at the web application firewall.
- Restrict access to /wp-admin/admin-ajax.php from unauthenticated and low-privilege sessions where feasible.
- Remove the vulnerable plugin files from disk if a business need for the plugin no longer exists.
# Example nginx rule to block the vulnerable AJAX actions
location = /wp-admin/admin-ajax.php {
if ($arg_action ~* "^(mtswpt_remove_plugin|ajax_update_export_code)$") {
return 403;
}
if ($request_body ~* "action=(mtswpt_remove_plugin|ajax_update_export_code)") {
return 403;
}
}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
