Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 05 Jan 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress |
|
| Vendors & Products |
Wordpress
Wordpress wordpress |
Fri, 02 Jan 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 31 Dec 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Ultimate Post Kit Addons for Elementor WordPress plugin before 4.0.16 exposes multiple AJAX “load more” endpoints such as upk_alex_grid_loadmore_posts without ensuring that posts to be displayed are published authentication. This allows an unauthenticated attacker to query arbitrary posts and retrieve rendered HTML content of private and unpublished ones. | |
| Title | Ultimate Post Kit < 4.0.16 – Unauthenticated Arbitrary Post Content Disclosure | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-01-02T14:37:14.868Z
Reserved: 2025-12-10T09:46:14.531Z
Link: CVE-2025-14434
Updated: 2026-01-02T14:20:46.244Z
Status : Deferred
Published: 2025-12-31T06:15:40.410
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-14434
No data.
OpenCVE Enrichment
Updated: 2026-01-05T10:17:55Z
No weakness.