Junglewise Threat Intelligence

CVE-2026-65472: Kit Kit (formerly ConvertKit) broken access control

CVE-2026-65472 · Severity: medium · CVSS 5.3 · Published 2026-07-23

Executive brief

The Kit (formerly ConvertKit) plugin for WordPress, which is used to integrate email marketing and lead generation tools into websites, contains a security flaw. This vulnerability allows unauthenticated individuals to perform actions that should be restricted to authorized users. While the impact is considered medium, it could allow unauthorized changes to certain plugin settings or data.

Technical details

The Kit (formerly ConvertKit) plugin for WordPress (versions <= 3.3.5) suffers from a broken access control vulnerability due to missing authorization checks (CWE-862). This flaw allows an unauthenticated remote attacker to execute functions that should be restricted to administrative users. The vulnerability is exploited via the network without requiring user interaction. While the CVSS score of 5.3 suggests limited impact (Integrity: Low, Confidentiality: None, Availability: None), it represents a failure in the plugin's permission model. The issue is resolved in version 3.3.6.

Affected products

  • Kit Kit (formerly ConvertKit) <= 3.3.5

Timeline

  • 2026-07-14: other: Reported by researcher Ananda Dhakal via Patchstack
  • 2026-07-22: advisory: Patchstack advisory published
  • 2026-07-23: disclosed: CVE published to NVD
  • 2026-07-23: patched: Version 3.3.6 released to address the issue

References