CVE-2025-12826

The Custom Post Type UI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.18.0. This is due to the plugin not verifying that a user has the required capability to perform actions in the "cptui_process_post_type" function. This makes it possible for authenticated attackers, with subscriber level access and above, to add, edit, or delete custom post types in limited situations.
Configurations

No configuration.

History

04 Dec 2025, 07:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-04 07:16

Updated : 2025-12-04 17:15


NVD link : CVE-2025-12826

Mitre link : CVE-2025-12826

CVE.ORG link : CVE-2025-12826


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization