AIKTP <= 5.0.04 - Missing Authorization to Authenticated (Subscriber+) Multiple Administrator Actions
mediumThe AIKTP plugin for WordPress is vulnerable to unauthorized modification of data due to missing authorization checks on the /aiktp/getToken REST API endpoint in all versions up to, and including, 5.0.04. The endpoint uses the 'verify_user_logged_in' as a permission callback, which only checks if a user is logged in, b...
- CVSS:
- 5.4
- Affected:
- up to 5.0.04
- Fixed in:
- 5.0.05
- Disclosed:
- Jan 23, 2026