Ultimate Post Kit Addons for Elementor <= 4.5.5 - Authenticated (Contributor+) Sensitive Information Exposure via Author Widget Social Links Setting

Medium 6.5 CWE-200Fixed in 4.5.6
ID
WPSEC-2026-0495
Plugin
Ultimate Post Kit – Elementor Post Grid, Post Carousel, Post Slider & Blog Layout Widgets (ultimate-post-kit)
Affected
from 1.5.0 before 4.5.6
Remediation
Update to 4.5.6 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness
CWE-200
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-07
Attack surface
Ultimate Post Kit Addons for Elementor on WPSec AttackSurface
Fix released
Published

Description

The Ultimate Post Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.5.5 via the Author widget's Social Links setting. This is due to saved social_links values being used as user field names in get_the_author_meta() without being checked against the widget's list of allowed contact methods. This makes it possible for authenticated attackers, with contributor-level access and above who can edit content with Elementor, to display the password hashes, usernames and other string user meta values of any site user, including administrators, in the widget's link output.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0