Description
Missing Authorization vulnerability in BdThemes Ultimate Post Kit ultimate-post-kit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Post Kit: from n/a through 4.5.5.
Published: 2026-10-08
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Modification of Content
Action: Patch Immediately
AI Analysis

Impact

The vulnerability is a broken access control flaw in BdThemes Ultimate Post Kit that allows an attacker to perform privileged operations such as creating, editing, or deleting posts and comments without proper authorization. This flaw permits an attacker to tamper with website content, potentially undermining the integrity of published material and the trust of site visitors.

Affected Systems

WordPress sites that have the BdThemes Ultimate Post Kit plugin installed in any version through 4.5.5 are vulnerable. The issue is linked to the plugin’s default configuration and may affect any user who can access the plugin’s administrative interface.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity, reflecting moderate impact on integrity and potential availability. The EPSS score is not available, so the likelihood of exploitation cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is internal or user‑based; based on the description, it is inferred that any authenticated user with insufficient privileges may be able to exercise the broken permissions, or that configuration errors could expose the privileged functions to all users.

Generated by OpenCVE AI on October 8, 2026 at 17:08 UTC.

Remediation

Vendor Solution

Update the WordPress Ultimate Post Kit plugin to the latest available version (at least 4.5.6).


OpenCVE Recommended Actions

  • Update the WordPress Ultimate Post Kit plugin to version 4.5.6 or later, the version that contains the fix for the broken access control flaw.
  • If an update is not immediately possible, disable or uninstall the plugin to eliminate the exposed capability until it can be patched.
  • Review the current user roles and capabilities on the site, ensuring that only users with administrator privileges can access and modify content through this plugin. If the plugin provides an option to restrict access levels, configure it to the strictest setting compatible with site operation.

Generated by OpenCVE AI on October 8, 2026 at 17:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 13:30:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in BdThemes Ultimate Post Kit ultimate-post-kit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Post Kit: from n/a through 4.5.5.
Title WordPress Ultimate Post Kit plugin <= 4.5.5 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-08T17:01:38.992Z

Reserved: 2026-10-06T00:18:26.657Z

Link: CVE-2026-105886

cve-icon Vulnrichment

Updated: 2026-10-08T17:01:35.380Z

cve-icon NVD

Status : Deferred

Published: 2026-10-08T13:17:13.403

Modified: 2026-10-08T17:24:11.230

Link: CVE-2026-105886

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T17:15:05Z

Weaknesses