PT-2026-26965 · WordPress · The Ultimate Wordpress Toolkit – Wp Extended
Hung Nguyen
·
Published
2026-03-22
·
Updated
2026-03-22
·
CVE-2026-4314
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
The Ultimate WordPress Toolkit – WP Extended versions prior to 3.2.4
Description
The 'The Ultimate WordPress Toolkit – WP Extended' plugin for WordPress is susceptible to a privilege escalation issue. This is caused by an insecure
strpos() check within the isDashboardOrProfileRequest() method against the $ SERVER['REQUEST URI'] variable, used to determine if a request targets the dashboard or profile page. The grantVirtualCaps() function, which is connected to the user has cap filter, grants elevated capabilities, including manage options, when this check returns true. Authenticated attackers with Subscriber-level access or higher can exploit this by adding a crafted query parameter to any admin URL, enabling them to update arbitrary WordPress options and create new Administrator accounts.Recommendations
Update 'The Ultimate WordPress Toolkit – WP Extended' to version 3.2.4 or later.
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
The Ultimate Wordpress Toolkit – Wp Extended