Kit (formerly ConvertKit) – Email Newsletter, Email Marketing, Membership, Subscribers and Landing Pages <= 3.4.5 - Authenticated (Contributor+) Missing Authorization to Kit Account Connection via OAuth Callback
- ID
- WPSEC-2026-0625
- Plugin
- Kit (formerly ConvertKit) – Email Newsletter, Email Marketing, Membership, Subscribers and Landing Pages (convertkit)
- Affected
- from 2.5.0 before 3.4.6
- Remediation
- Update to 3.4.6 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
- Weakness
- CWE-862
- Usage
- Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-08
- Attack surface
- Kit (formerly ConvertKit) – Email Newsletter, Email Marketing, Membership, Subscribers and Landing Pages on WPSec AttackSurface
- Fix released
- Published
Description
The Kit (formerly ConvertKit) plugin for WordPress is vulnerable to unauthorized modification of data in versions 2.5.0 up to, and including, 3.4.5. The OAuth callback on the plugin's settings screen, which runs on the admin_init hook while the site is not yet connected to Kit, has no capability check and does not verify that the request came from the plugin. This makes it possible for authenticated attackers, with contributor-level access and above, to use the connection link the plugin shows them to authorize their own Kit account and connect the site to it. Once connected, subscriber sign-ups and form data the site collects are sent to the attacker's Kit account.
References
- https://wpsec.com/vuln/WPSEC-2026-0625/
- https://plugins.svn.wordpress.org/convertkit/tags/3.4.6/
- https://wordpress.org/plugins/convertkit/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS