What the vulnerability does
01Description
The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the module_all_toggle_ajax() function in all versions up to, and including, 3.0.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.
Explanation of Vulnerability in Simple Terms
02Summary
The Ultimate WordPress Toolkit plugin for WordPress contains a missing authorization check that allows authenticated users with low privileges to perform actions they should not have access to. An attacker with a basic user account can read sensitive data, modify site content, or disrupt site availability. All versions up to 3.0.8 are affected. Site administrators should update immediately to a patched version.
What an attacker can do
03Attacker Capabilities
Read sensitive data, modify content, or disrupt site availability with a low-privilege user account.
Potential impact on your site
04Site Impact
Compromised data confidentiality, content integrity, and site availability if any user account is breached or misused.
Conditions required to exploit
05Prerequisites
Attacker must have a valid WordPress user account with low privileges (e.g., subscriber or contributor role).
Key dates
06Disclosure timeline
September 4, 2024
CVE published
April 8, 2026
Record updated