Sceawere

Vulnerability Detail

CVE-2026-25403UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Ultimate Store Kit Access Control Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
1d ago
Vendor
bdthemes
Product
Ultimate Store Kit Elementor Addons
Attack Type
CWE-862 Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Broken Access Control in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-08-06T15:16:51.320Z",
  "pubdate": "2026-08-06T15:16:51.320Z",
  "executiveSummary": "An unauthenticated broken access control vulnerability has been identified in the Ultimate Store Kit Elementor Addons plugin. This security flaw allows unauthenticated remote threat actors to bypass standard authorization checks and interact with restricted functionalities or resources exposed by the plugin.\nThe affected product is Ultimate Store Kit Elementor Addons for versions 3.0.5 and below. The risk implications are severe, as successful exploitation does not require valid credentials or user interaction, lowering the attack barrier significantly.\nThe primary impact involves unauthorized access, potentially leading to unauthorized data exposure, modification, or functional abuse depending on the underlying exposed endpoints. Threat actors with network visibility can leverage this flaw directly via HTTP requests to target installations.\nBecause the vulnerability stems from missing or improper authorization enforcement within the plugin's codebase, remediation requires updating the software to a patched version once available or restricting access to vulnerable endpoints.",
  "technicalDetails": "The root cause of the vulnerability lies in broken access control implementation within the Ultimate Store Kit Elementor Addons <= 3.0.5 versions. Specifically, the affected component fails to adequately validate the identity and authorization level of incoming requests before executing sensitive backend logic or rendering restricted data.\nThe vulnerability is exposed over the network via HTTP/HTTPS protocols, characteristic of WordPress plugin architecture. Since the flaw is unauthenticated, no session cookies, nonces, or privilege requirements are enforced by the vulnerable functions or REST API endpoints.\nThe attack flow proceeds as follows: First, an unauthenticated attacker identifies the target WordPress site running a vulnerable version of Ultimate Store Kit Elementor Addons. Second, the attacker crafts a malicious HTTP request targeting the improperly secured endpoint or AJAX action exposed by the plugin.\nThird, because the application lacks proper capability checks or role verification, the backend processes the request as if it originated from an authorized user. Finally, the server responds with the requested sensitive data or executes the unintended backend operation, achieving the attacker's objective.\nPayload behavior depends on the specific endpoint targeted, but generally involves bypassing authorization barriers to interact with administrative or restricted features. Post-exploitation impact includes potential unauthorized information disclosure, unauthorized state changes, or further system compromise depending on what capabilities are improperly exposed."
}
CVE-2026-25403: Ultimate Store Kit Access Control Vulnerability (MEDIUM Severity, CVSS: 6.5) - Sceawere