UiPress lite | Effortless custom dashboards, admin themes and pages vulnerability

The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'uip_save_ui_template' function in all versions up to, and including, 3.5.09. This makes it possible for authenticated attackers, with Subscriber-level access and above, to save templates that contain custom JavaScript.

Published 21 Nov 2025Updated 14 Sep 20264 sources
CVSS 6.4

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.