Unauthorized Data Modification in UiPress Lite Plugin for WordPress
CVE-2026-2294
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 21 March 2026
What is CVE-2026-2294?
The UiPress Lite plugin for WordPress, which simplifies the creation of custom dashboards and admin pages, contains a flaw that allows authenticated users with Subscriber-level access or higher to modify plugin settings. This vulnerability arises from a missing capability check within the 'uip_save_global_settings' function, making it possible for attackers to change arbitrary settings without proper authorization. This impacts all versions of UiPress Lite up to and including version 3.5.09.
Affected Version(s)
UiPress lite | Effortless custom dashboards, admin themes and pages 0 <= 3.5.09