Missing Authorization Vulnerability in bdthemes Ultimate Post Kit
CVE-2026-24362
6.4MEDIUM
What is CVE-2026-24362?
The Missing Authorization vulnerability in bdthemes Ultimate Post Kit affects improperly configured access control security levels, allowing unauthorized access to sensitive features. This issue impacts versions of the Ultimate Post Kit from its initial release up to and including version 4.0.21, posing significant security risks to WordPress websites utilizing the plugin.
Affected Version(s)
Ultimate Post Kit 0 <= 4.0.21