{"id":"CVE-2025-12826","summary":"Custom Post Type UI \u003c= 1.18.0 - Missing Authorization to Unauthenticated (Previously Administrator+) Custom Post Type Modification","details":"The Custom Post Type UI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.18.0. This is due to the plugin not verifying that a user has the required capability to perform actions in the \"cptui_process_post_type\" function. This makes it possible for authenticated attackers, with subscriber level access and above, to add, edit, or delete custom post types in limited situations.","modified":"2026-08-12T03:51:25.985166684Z","published":"2025-12-04T06:48:40.592Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/12xxx/CVE-2025-12826.json","cna_assigner":"Wordfence","cwe_ids":["CWE-862"]},"references":[{"type":"WEB","url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/90d203b1-9426-4eff-b566-02c8a1c6adfa?source=cve"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/12xxx/CVE-2025-12826.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-12826"},{"type":"FIX","url":"https://github.com/WebDevStudios/custom-post-type-ui/commit/215779a5ac0c624f0dcf875e87305b4898d5bcf9"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/webdevstudios/custom-post-type-ui","events":[{"introduced":"0"},{"fixed":"215779a5ac0c624f0dcf875e87305b4898d5bcf9"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"1.18.0"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["1.18.0","1.17.3","1.17.2","1.17.1","1.17.0","1.16.0","1.15.1","1.15.0","1.14.0","1.13.7","1.13.6","1.13.5","1.13.4","1.13.3","1.13.2","1.13.1","1.13.0","1.12.1","1.12.0","1.11.2","1.11.1","1.11.0","1.10.2","1.10.1","1.10.0","1.9.2","1.9.1","1.9.0","1.8.2","1.8.1","1.8.0","1.7.5","1.7.4","1.7.2","1.7.1","1.7.0","1.6.1","1.5.1","1.5.0","1.4.1","1.4.0","1.3.3","1.3.2","1.3.1","1.3.0","1.2.4","1.2.3","1.2.2","1.2.1","1.2.0","1.1.3","1.1.2","1.1.1","1.1","1.0.8","1.0.7","1.0.5","1.0.4","1.0.2","1.0.1","1.0.0","0.9.0","0.8.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-12826.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L"}]}