THREAT OPS › Threat News › [NVD] CVE-2025-10938 (MEDIUM 6.5) — The UiPress lite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.08. This is due to missing capability checks in the 'uip_process_block_query' AJAX function. This makes it possible for authenticated attackers, with su
[NVD] CVE-2025-10938 (MEDIUM 6.5) — The UiPress lite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.08. This is due to missing capability checks in the 'uip_process_block_query' AJAX function. This makes it possible for authenticated attackers, with su
CVE-2025-10938 CVSS: 6.5 MEDIUM Published: 2025-11-21T08:15:48.083
The UiPress lite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.08. This is due to missing capability checks in the 'uip_process_block_query' AJAX function. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract sensitiv
Indicators of compromise
- CVE-2025-10938cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-10938