Sensitive Information Exposure in Virusdie Website Security Plugin for WordPress
CVE-2025-14864
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 19 February 2026
What is CVE-2025-14864?
The Virusdie one-click website security plugin for WordPress is susceptible to a vulnerability that allows authenticated users with Subscriber-level access or higher to exploit missing capability checks within the 'vd_get_apikey' function. By invoking this function through the 'wp_ajax_virusdie_apikey' hook, these attackers can access sensitive site information, specifically the Virusdie API key. This access potentially enables them to control account actions and compromise the overall security of the website, putting site owners at risk of further attacks. It is recommended to upgrade to the most recent version of the plugin to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Virusdie β One-click website security * <= 1.1.7
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved