{
 "id": "WPSEC-2026-0495",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0495/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0495/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0495/index.md",
 "title": "Ultimate Post Kit Addons for Elementor <= 4.5.5 - Authenticated (Contributor+) Sensitive Information Exposure via Author Widget Social Links Setting",
 "description": "The Ultimate Post Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.5.5 via the Author widget's Social Links setting. This is due to saved social_links values being used as user field names in get_the_author_meta() without being checked against the widget's list of allowed contact methods. This makes it possible for authenticated attackers, with contributor-level access and above who can edit content with Elementor, to display the password hashes, usernames and other string user meta values of any site user, including administrators, in the widget's link output.",
 "plugin": {
  "slug": "ultimate-post-kit",
  "name": "Ultimate Post Kit Addons for Elementor",
  "full_name": "Ultimate Post Kit – Elementor Post Grid, Post Carousel, Post Slider & Blog Layout Widgets",
  "wordpress_org": "https://wordpress.org/plugins/ultimate-post-kit/",
  "advisories_url": "https://wpsec.com/vuln/plugin/ultimate-post-kit/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/ultimate-post-kit"
 },
 "type": "SENSITIVE DATA DISCLOSURE",
 "cwe": [
  "CWE-200"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 6.5,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": "1.5.0",
    "from_inclusive": true,
    "to": "4.5.6",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 1.5.0 before 4.5.6"
  ]
 },
 "introduced_in": "1.5.0",
 "fixed_in": "4.5.6",
 "remediation": "Update to 4.5.6 or later.",
 "fix_released": "2026-10-06T08:37:16+00:00",
 "published": "2026-10-07T08:42:58+00:00",
 "updated": "2026-10-06T16:46:16.652390+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0495/",
  "https://plugins.svn.wordpress.org/ultimate-post-kit/tags/4.5.6/",
  "https://wordpress.org/plugins/ultimate-post-kit/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/ultimate-post-kit",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Medium",
  "affected_versions": "Medium",
  "as_of": "2026-10-07"
 }
}