CVE · Medium

CVE-2025-12826 — Custom Post Type UI [custom-post-type-ui] < 1.18.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-12826 Custom Post Type UI [custom-post-type-ui] < 1.18.1 Missing Authorization Medium 4.8 < 1.18.1 1.18.1 2025-12-03

CVE-2025-12826

The Custom Post Type UI plugin for WordPress is susceptible to an authorization bypass vulnerability affecting all versions up to 1.18.0. The issue arises because the plugin fails to properly verify user capabilities within the "cptui_process_post_type" function, allowing authenticated users with subscriber-level access or higher to potentially manipulate custom post types under certain conditions.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.