The Ultimate Post Kit Addons for Elementor WordPress plugin before 4.0.16 exposes multiple AJAX “load more” endpoints such as upk_alex_grid_loadmore_posts without ensuring that posts to be displayed are published authentication. This allows an unauthenticated attacker to query arbitrary posts and retrieve rendered HTML content of private and unpublished ones.
Metrics
Affected Vendors & Products
References
History
Mon, 05 Jan 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress |
|
| Vendors & Products |
Wordpress
Wordpress wordpress |
Fri, 02 Jan 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 31 Dec 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Ultimate Post Kit Addons for Elementor WordPress plugin before 4.0.16 exposes multiple AJAX “load more” endpoints such as upk_alex_grid_loadmore_posts without ensuring that posts to be displayed are published authentication. This allows an unauthenticated attacker to query arbitrary posts and retrieve rendered HTML content of private and unpublished ones. | |
| Title | Ultimate Post Kit < 4.0.16 – Unauthenticated Arbitrary Post Content Disclosure | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published: 2025-12-31T06:00:11.262Z
Updated: 2026-01-02T14:37:14.868Z
Reserved: 2025-12-10T09:46:14.531Z
Link: CVE-2025-14434
Updated: 2026-01-02T14:20:46.244Z
Status : Awaiting Analysis
Published: 2025-12-31T06:15:40.410
Modified: 2026-01-02T15:15:57.800
Link: CVE-2025-14434
No data.
ReportizFlow