The UiPress lite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.08. This is due to missing capability checks in the 'uip_process_block_query' AJAX function. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract sensitive user data including password hashes, emails, and other user information that could be used for account takeover attacks.
We have discovered 5 live websites that are affected by CVE-2025-10938.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 5 live websites (63% of Uipress Lite install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 1 versions ( 50% of all versions) |
| 1 websites | |
| 1 websites | |
| 1 websites | |
| 1 websites | |
| 1 websites |
| .com | 3 websites |
| .com.br | 1 websites |
| .fi | 1 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *************.***.br | **,***,*** | ||
| **********.com | **,***,*** | ||
| *****.fi | **,***,*** | ||
| **.********.com | **,***,*** | ||
| *****.com | ***,***,*** |
FAQ