CVE-2025-10938
BaseFortify
Publication date: 2025-11-21
Last updated on: 2025-11-21
Assigner: Wordfence
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| wordpress | ui_press_lite | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-862 | The product does not perform an authorization check when an actor attempts to access a resource or perform an action. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
The vulnerability in the UiPress lite plugin for WordPress allows authenticated users with subscriber-level access or higher to exploit missing capability checks in the 'uip_process_block_query' AJAX function. This flaw enables them to extract sensitive user data such as password hashes, emails, and other user information.
How can this vulnerability impact me? :
This vulnerability can lead to sensitive information exposure, allowing attackers to obtain password hashes, emails, and other user data. Such information could be used to perform account takeover attacks, compromising user accounts and potentially leading to unauthorized access to the affected WordPress site.