Executive brief
UiPress Lite is a WordPress plugin used to build custom website interfaces and dashboards. A missing permission check in the plugin allows authenticated users with basic subscriber-level access to retrieve sensitive data including password hashes and email addresses of other users, potentially enabling account takeover attacks.
Technical details
The vulnerability is a missing capability check in the 'uip_process_block_query' AJAX function. An authenticated attacker with subscriber-level privileges or higher can invoke this function without proper authorization to extract sensitive user data including password hashes, email addresses, and other user account information. The vulnerability affects all versions up to and including 3.5.08. The attack requires authentication (subscriber account) and network access to the WordPress site, but no additional user interaction. Patches are available in versions after 3.5.08.
Affected products
- UiPress Lite up to and including 3.5.08
Timeline
- 2025-11-21: disclosed