The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'uip_save_global_settings' function in all versions up to, and including, 3.5.09. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change arbitrary plugin settings.
We have discovered 11 live websites that are affected by CVE-2026-2294.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 11 live websites (100% of Uipress Lite install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 2 versions ( 100% of all versions) |
| 4 websites | |
| 1 websites | |
| 1 websites | |
| 1 websites | |
| 1 websites | |
| 1 websites | |
| 1 websites | |
| 1 websites |
| .com | 6 websites |
| .com.br | 1 websites |
| .fi | 1 websites |
| .net | 1 websites |
| .org | 1 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *********.net | **,***,*** | ||
| **********.com | **,***,*** | ||
| *****************.com | **,***,*** | ||
| *************.***.br | **,***,*** | ||
| **********.com | **,***,*** | ||
| ***********.ie | **,***,*** | ||
| *****.fi | **,***,*** | ||
| **.********.com | **,***,*** | ||
| *************.com | **,***,*** | ||
| ***********.org | **,***,*** |
FAQ