Unauthenticated Access Control Vulnerability in Ultimate Store Kit by WordPress
CVE-2026-25403

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
6 August 2026

What is CVE-2026-25403?

The Ultimate Store Kit Elementor Addons plugin for WordPress has a vulnerability that allows unauthenticated users to exploit broken access control mechanisms. This issue affects versions up to and including 3.0.5, potentially allowing unauthorized access to sensitive functions and data within the plugin, compromising the security of the website. It is essential for users to update to the latest version and implement best security practices to safeguard their web applications.

Affected Version(s)

Ultimate Store Kit Elementor Addons <= 3.0.5

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bao - BlueRock | Patchstack Bug Bounty Program
.