Custom Post Type UI [custom-post-type-ui] < 1.18.2
unknown
[en] The Custom Post Type UI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'label' parameter during custom post type import in all versions up to, and including, 1.18.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Admini...
- Affected:
- up to 1.18.2
- Fixed in:
- 1.18.2
- Disclosed:
- Dec 13, 2025
CVE-2025-14056 on NVD →
Custom Post Type UI <= 1.18.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'label' Import Parameter
medium
The Custom Post Type UI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'label' parameter during custom post type import in all versions up to, and including, 1.18.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrat...
- CVSS:
- 4.4
- Affected:
- up to 1.18.1
- Fixed in:
- 1.18.2
- Disclosed:
- Dec 12, 2025
CVE-2025-14056 on NVD →
Custom Post Type UI [custom-post-type-ui] < 1.18.1
unknown
[en] The Custom Post Type UI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.18.0. This is due to the plugin not verifying that a user has the required capability to perform actions in the "cptui_process_post_type" function. This makes it possible for authenticated att...
- Affected:
- up to 1.18.1
- Fixed in:
- 1.18.1
- Disclosed:
- Dec 4, 2025
CVE-2025-12826 on NVD →
Custom Post Type UI <= 1.18.0 - Missing Authorization to Unauthenticated (Previously Administrator+) Custom Post Type Modification
medium
The Custom Post Type UI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.18.0. This is due to the plugin not verifying that a user has the required capability to perform actions in the "cptui_process_post_type" function. This makes it possible for authenticated attacker...
- CVSS:
- 4.8
- Affected:
- up to 1.18.0
- Fixed in:
- 1.18.1
- Disclosed:
- Dec 3, 2025
CVE-2025-12826 on NVD →
Custom Post Type UI [custom-post-type-ui] < 1.13.5
unknown
[en] The Custom Post Type UI WordPress plugin before 1.13.5 does not properly check for CSRF when sending the debug information to a user supplied email, which could allow attackers to make a logged in admin send such information to an arbitrary email address via a CSRF attack.
- Affected:
- up to 1.13.5
- Fixed in:
- 1.13.5
- Disclosed:
- Apr 24, 2023
CVE-2023-1623 on NVD →
Custom Post Type UI [custom-post-type-ui] < 1.13.5
unknown
Update the WordPress Custom Post Type UI plugin to the latest available version (at least 1.13.5).
Unknown discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Custom Post Type UI Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions...
- Affected:
- up to 1.13.5
- Fixed in:
- 1.13.5
- Disclosed:
- Mar 30, 2023
Custom Post Type UI <= 1.13.4 - Cross-Site Request Forgery to Sensitive Information Exposure
medium
The Custom Post Type UI for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.13.4 . This is due to missing or incorrect nonce validation in the cptui_render_debuginfo_section function. This makes it possible for unauthenticated attackers to exfiltrate debug information gathered...
- CVSS:
- 5.4
- Affected:
- up to 1.13.4
- Fixed in:
- 1.13.5
- Disclosed:
- Mar 28, 2023
CVE-2023-1623 on NVD →
Custom Post Type UI <= 1.7.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting
high
The Custom Post Type UI plugin for WordPress is vulnerable to Cross-Site Request forgery in versions up to, and including 1.7.3, due missing nonce validation on the import functionality that makes it possible for attackers to trick site administrators into performing unwanted actions such as importing new post types co...
- CVSS:
- 8.8
- Affected:
- up to 1.7.4
- Fixed in:
- 1.7.4
- Disclosed:
- Mar 18, 2020
Custom Post Type UI [custom-post-type-ui] < 1.7.4
unknown
The Custom Post Type UI plugin for WordPress is vulnerable to Cross-Site Request forgery in versions up to, and including 1.7.3, due missing nonce validation on the import functionality that makes it possible for attackers to trick site administrators into performing unwanted actions such as importing new post types co...
- Affected:
- up to 1.7.4
- Fixed in:
- 1.7.4
- Disclosed:
- Mar 18, 2020
Custom Post Type UI [custom-post-type-ui] < 1.7.4
unknown
Cross-Site Request Forgery (CSRF) vulnerability leading to Stored Cross-Site Scripting (XSS) discovered in WordPress Custom Post Type UI plugin (versions <= 1.7.3).
- Affected:
- up to 1.7.4
- Fixed in:
- 1.7.4
- Disclosed:
- Mar 17, 2020
Custom Post Type UI [custom-post-type-ui] < 1.7.4
unknown
The Custom Post Type UI WordPress plugin was vulnerable to Cross-Site Request Forgery (CSRF) and Stored Cross-Site Scripting (XSS) within the "Import Post Types" functionality in the "Tools" tab. This functionality allows users to import "Post Types" from other websites, or from backup, as...
- Affected:
- up to 1.7.4
- Fixed in:
- 1.7.4
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database