CVE-2026-4314Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 5 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The 'The Ultimate WordPress Toolkit – WP Extended' plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.2.4. This is due to the `isDashboardOrProfileRequest()` method in the Menu Editor module using an insecure `strpos()` check against `$_SERVER['REQUEST_URI']` to determine if a request targets the dashboard or profile page. The `grantVirtualCaps()` method, which is hooked into the `user_has_cap` filter, grants elevated capabilities including `manage_options` when this check returns true. This makes it possible for authenticated attackers, with Subscriber-level access and above, to gain administrative capabilities by appending a crafted query parameter to any admin URL, allowing them to update arbitrary WordPress options and ultimately create new Administrator accounts.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 5 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 5 classified signals
  • 5 total mentions across 1 day

Deep dive

Activity timeline5 mentions / 1d
01345Mentions · 2026-03-22: 5Technical Details · 2026-03-22: 303-22
Signal classification1 categories
Disclosure
5100.0%
Referenced assets5 URLs
Full discourse5 posts
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-4314 - High The 'The Ultimate WordPress Toolkit – WP Extended' plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.2.4. This is due to the `isDashboardOrPr... https://www.thehackerwire.com/vulnerability/CVE-2026-4314/ https://t.co/ozE06xPvFI

    Post summary

    The text reports a high‑severity CVE‑2026‑4314 affecting the Ultimate WordPress Toolkit – WP Extended plugin, highlighting privilege escalation across versions up to 3.2.4, with no proof of exploitation or remedial guidance mentioned.

    0000051
    144 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-4314 📊 Severity: 8.8 🚨 Risk Level: High 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4314 #CVE-2026-4314 #CVE #High #Wordpress #CyberSecurity #InfoSec https://t.co/3Zh8XDUstS

    Post summary

    The tweet simply announces a new high‑severity CVE (CVE‑2026‑4314) affecting WordPress and directs readers to the NVD entry.

    0000023
    111 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4314 The 'The Ultimate WordPress Toolkit – WP Extended' plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.2.4. This is due t… https://www.cve.org/CVERecord?id=CVE-2026-4314

    Post summary

    A new vulnerability (CVE‑2026‑4314) affecting 'The Ultimate WordPress Toolkit – WP Extended' up to version 3.2.4 has been disclosed, specifying a privilege escalation flaw; no PoC, exploit, patch, or active exploitation details are mentioned.

    0000075
    56.8K followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-4314 - wpextended - The Ultimate WordPress Toolkit – WP Extended - https://www.redpacketsecurity.com/cve-alert-cve-2026-4314-wpextended-the-ultimate-wordpress-toolkit-wp-extended/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-4314 #wpextended #the-ultimate-wordpress-toolkit-wp-extended

    Post summary

    The post is a CVE alert announcing CVE‑2026‑4314 for the WP Extended plugin, providing a link for further details but offering no PoC, exploit, patch, or technical specifics.

    0000068
    3.6K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-4314: HIGH] Vulnerability alert: 'Ultimate WordPress Toolkit - WP Extended' plugin allows privileged escalation up to version 3.2.4. Attackers can gain admin access, jeopardizing website security.#cve,CVE-2026-4314,#cybersecurity https://cvefind.com/CVE-2026-4314

    Post summary

    A vulnerability alert for CVE-2026-4314 reports privileged escalation in the Ultimate WordPress Toolkit "WP Extended" plugin, enabling attackers to obtain admin access up to version 3.2.4.

    0000051
    605 followersView on X

Explore more