Kit (formerly ConvertKit) – Email Newsletter, Email Marketing, Membership, Subscribers and Landing Pages <= 3.4.5 - Authenticated (Contributor+) Missing Authorization to Kit Account Connection via OAuth Callback

Medium 4.2 CWE-862Fixed in 3.4.6
ID
WPSEC-2026-0625
Plugin
Kit (formerly ConvertKit) – Email Newsletter, Email Marketing, Membership, Subscribers and Landing Pages (convertkit)
Affected
from 2.5.0 before 3.4.6
Remediation
Update to 3.4.6 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Weakness
CWE-862
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-08
Attack surface
Kit (formerly ConvertKit) – Email Newsletter, Email Marketing, Membership, Subscribers and Landing Pages on WPSec AttackSurface
Fix released
Published

Description

The Kit (formerly ConvertKit) plugin for WordPress is vulnerable to unauthorized modification of data in versions 2.5.0 up to, and including, 3.4.5. The OAuth callback on the plugin's settings screen, which runs on the admin_init hook while the site is not yet connected to Kit, has no capability check and does not verify that the request came from the plugin. This makes it possible for authenticated attackers, with contributor-level access and above, to use the connection link the plugin shows them to authorize their own Kit account and connect the site to it. Once connected, subscriber sign-ups and form data the site collects are sent to the attacker's Kit account.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0