Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
4.3

Unauthorized Changes to WordPress Plugin Settings

CVE-2026-2294
Summary

The UiPress lite plugin for WordPress is vulnerable to unauthorized changes to its settings by users with Subscriber-level access or higher. This means that an attacker could alter the plugin's settings, potentially affecting the security and functionality of the site. To protect your site, update the plugin to the latest version.

Original title
The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'uip_save_gl...
Original description
The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'uip_save_global_settings' function in all versions up to, and including, 3.5.09. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change arbitrary plugin settings.
nvd CVSS3.1 4.3
Vulnerability type
CWE-285 Improper Authorization
Published: 21 Mar 2026 · Updated: 21 Mar 2026 · First seen: 21 Mar 2026