THREATOPS
THREAT OPSThreat News › [NVD] CVE-2025-10938 (MEDIUM 6.5) — The UiPress lite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.08. This is due to missing capability checks in the 'uip_process_block_query' AJAX function. This makes it possible for authenticated attackers, with su

[NVD] CVE-2025-10938 (MEDIUM 6.5) — The UiPress lite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.08. This is due to missing capability checks in the 'uip_process_block_query' AJAX function. This makes it possible for authenticated attackers, with su

lownvdPublished 2025-11-21

CVE-2025-10938 CVSS: 6.5 MEDIUM Published: 2025-11-21T08:15:48.083

The UiPress lite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.08. This is due to missing capability checks in the 'uip_process_block_query' AJAX function. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract sensitiv

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-10938