CVE-2026-105886: WordPress Ultimate Post Kit plugin <= 4.5.5 - Broken Access Control vulnerability
Missing Authorization vulnerability in BdThemes Ultimate Post Kit ultimate-post-kit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Post Kit: from n/a through 4.5.5.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/ultimate-post-kitto a version that resolves this vulnerability.Fixed in 4.5.6
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The vulnerability requires low-privileged access, as indicated by PR:L in the CVSS vector. It does not require user interaction and can be exploited over the network.
What security impact is identified?
The reported impact is high confidentiality impact, with no identified integrity or availability impact. Successful exploitation could expose information accessible through incorrectly configured authorization controls.
Which Ultimate Post Kit versions are affected?
Ultimate Post Kit versions through 4.5.5 are affected. The available data does not identify a fixed version.