{
 "id": "WPSEC-2026-0625",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0625/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0625/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0625/index.md",
 "title": "Kit (formerly ConvertKit) – Email Newsletter, Email Marketing, Membership, Subscribers and Landing Pages <= 3.4.5 - Authenticated (Contributor+) Missing Authorization to Kit Account Connection via OAuth Callback",
 "description": "The Kit (formerly ConvertKit) plugin for WordPress is vulnerable to unauthorized modification of data in versions 2.5.0 up to, and including, 3.4.5. The OAuth callback on the plugin's settings screen, which runs on the admin_init hook while the site is not yet connected to Kit, has no capability check and does not verify that the request came from the plugin. This makes it possible for authenticated attackers, with contributor-level access and above, to use the connection link the plugin shows them to authorize their own Kit account and connect the site to it. Once connected, subscriber sign-ups and form data the site collects are sent to the attacker's Kit account.",
 "plugin": {
  "slug": "convertkit",
  "name": "Kit (formerly ConvertKit) – Email Newsletter, Email Marketing, Membership, Subscribers and Landing Pages",
  "full_name": "Kit (formerly ConvertKit) – Email Newsletter, Email Marketing, Membership, Subscribers and Landing Pages",
  "wordpress_org": "https://wordpress.org/plugins/convertkit/",
  "advisories_url": "https://wpsec.com/vuln/plugin/convertkit/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/convertkit"
 },
 "type": "NO AUTHORISATION",
 "cwe": [
  "CWE-862"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 4.2,
  "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": "2.5.0",
    "from_inclusive": true,
    "to": "3.4.6",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 2.5.0 before 3.4.6"
  ]
 },
 "introduced_in": "2.5.0",
 "fixed_in": "3.4.6",
 "remediation": "Update to 3.4.6 or later.",
 "fix_released": "2026-10-07T09:35:55+00:00",
 "published": "2026-10-08T09:45:16+00:00",
 "updated": "2026-10-07T11:59:30.645119+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0625/",
  "https://plugins.svn.wordpress.org/convertkit/tags/3.4.6/",
  "https://wordpress.org/plugins/convertkit/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/convertkit",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Medium",
  "affected_versions": "Medium",
  "as_of": "2026-10-08"
 }
}