# Ultimate Post Kit Addons for Elementor <= 4.5.5 - Authenticated (Contributor+) Sensitive Information Exposure via Author Widget Social Links Setting

- **ID:** WPSEC-2026-0495
- **Plugin:** Ultimate Post Kit – Elementor Post Grid, Post Carousel, Post Slider & Blog Layout Widgets (`ultimate-post-kit`), https://wordpress.org/plugins/ultimate-post-kit/
- **Affected versions:** from 1.5.0 before 4.5.6
- **Fixed in:** 4.5.6 (Update to 4.5.6 or later.)
- **Severity:** Medium 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
- **Weakness:** CWE-200
- **Usage among sites WPSec scans:** plugin Medium, affected versions Medium (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/ultimate-post-kit
- **Fix released:** 2026-10-06
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0495/

## Description

The Ultimate Post Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.5.5 via the Author widget's Social Links setting. This is due to saved social_links values being used as user field names in get_the_author_meta() without being checked against the widget's list of allowed contact methods. This makes it possible for authenticated attackers, with contributor-level access and above who can edit content with Elementor, to display the password hashes, usernames and other string user meta values of any site user, including administrators, in the widget's link output.

## References

- https://wpsec.com/vuln/WPSEC-2026-0495/
- https://plugins.svn.wordpress.org/ultimate-post-kit/tags/4.5.6/
- https://wordpress.org/plugins/ultimate-post-kit/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0495/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
