The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'uip_save_ui_template' function in all versions up to, and including, 3.5.08. This makes it possible for authenticated attackers, with Subscriber-level access and above, to save templates that contain custom JavaScript.
We have discovered 5 live websites that are affected by CVE-2025-11003.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 5 live websites (63% of Uipress Lite install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 1 versions ( 50% of all versions) |
| 1 websites | |
| 1 websites | |
| 1 websites | |
| 1 websites | |
| 1 websites |
| .com | 3 websites |
| .com.br | 1 websites |
| .fi | 1 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *************.***.br | **,***,*** | ||
| **********.com | **,***,*** | ||
| *****.fi | **,***,*** | ||
| **.********.com | **,***,*** | ||
| *****.com | ***,***,*** |
FAQ