# CVE-2025-10938

## Summary

- **CVE ID:** CVE-2025-10938
- **Severity:** MEDIUM
- **CVSS Score:** 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
- **CWE:** CWE-862
- **Published:** Nov 21, 2025
- **Last Modified:** Sep 14, 2026

## Description

The UiPress lite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.08. This is due to missing capability checks in the 'uip_process_block_query' AJAX function. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract sensitive user data including password hashes, emails, and other user information that could be used for account takeover attacks.

## Affected Products

- admintwentytwenty — UiPress lite | Effortless custom dashboards, admin themes and pages (*)
- admintwentytwenty — UiPress lite | Effortless custom dashboards, admin themes and pages (0)

## References

- [CNA](https://www.wordfence.com/threat-intel/vulnerabilities/id/d8aa06eb-774a-4cd9-bd35-2d6409475696?source=cve)
- [CNA](https://wordpress.org/plugins/uipress-lite/)
- [CNA](https://plugins.trac.wordpress.org/changeset/3654103/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.25%
- **EPSS Percentile:** 16.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-19._