Ultimate Post Kit Addons for Elementor <= 4.5.5 - Authenticated (Contributor+) Sensitive Information Exposure via Author Widget Social Links Setting
- ID
- WPSEC-2026-0495
- Plugin
- Ultimate Post Kit – Elementor Post Grid, Post Carousel, Post Slider & Blog Layout Widgets (ultimate-post-kit)
- Affected
- from 1.5.0 before 4.5.6
- Remediation
- Update to 4.5.6 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Weakness
- CWE-200
- Usage
- Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-07
- Attack surface
- Ultimate Post Kit Addons for Elementor on WPSec AttackSurface
- Fix released
- Published
Description
The Ultimate Post Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.5.5 via the Author widget's Social Links setting. This is due to saved social_links values being used as user field names in get_the_author_meta() without being checked against the widget's list of allowed contact methods. This makes it possible for authenticated attackers, with contributor-level access and above who can edit content with Elementor, to display the password hashes, usernames and other string user meta values of any site user, including administrators, in the widget's link output.
References
- https://wpsec.com/vuln/WPSEC-2026-0495/
- https://plugins.svn.wordpress.org/ultimate-post-kit/tags/4.5.6/
- https://wordpress.org/plugins/ultimate-post-kit/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS