WPMasterToolKit <= 2.14.0 - Missing Authorization
medium
The WPMasterToolKit (WPMTK) – All in one plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.14.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized a...
- CVSS:
- 4.3
- Affected:
- up to 2.14.0
- Fixed in:
- 2.14.1
- Disclosed:
- Jan 15, 2026
CVE-2026-24388 on NVD →
WPMasterToolKit (WPMTK) <= 2.13.0 - Authenticated (Contributor+) Code Injection
medium
The WPMasterToolKit plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 2.13.0. This is due to the plugin allowing Author-level users to create and execute arbitrary PHP code through the Code Snippets feature without proper capability checks. This makes it possible for authent...
- CVSS:
- 5.3
- Affected:
- up to 2.13.0
- Fixed in:
- 2.13.1
- Disclosed:
- Dec 11, 2025
CVE-2025-14166 on NVD →
WPMasterToolKit (WPMTK) – All in one plugin <= 2.5.2 - Authenticated (Administrator+) to Arbitrary File Read and Write
high
The WPMasterToolKit (WPMTK) – All in one plugin plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.5.2. This makes it possible for authenticated attackers, with Administrator-level access and above, to read and modify the contents of arbitrary files on the server, which ca...
- CVSS:
- 7.2
- Affected:
- up to 1.15.0
- Fixed in:
- 2.6.0
- Disclosed:
- Apr 23, 2025
CVE-2025-3300 on NVD →
WPMasterToolKit <= 1.13.1 - Authenticated (Admin+) Arbitrary File Upload
high
The WPMasterToolKit (WPMTK) – All in one plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 1.13.1. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the...
- CVSS:
- 7.2
- Affected:
- up to 1.13.1
- Fixed in:
- 1.14.0
- Disclosed:
- Dec 30, 2024
CVE-2024-56249 on NVD →
WPMasterToolKit <= 1.13.1 - Authenticated (Admin+) Arbitrary File Download
medium
The WPMasterToolKit (WPMTK) – All in one plugin plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.13.1. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary files on the server, which can contain...
- CVSS:
- 4.9
- Affected:
- up to 1.13.1
- Fixed in:
- 1.14.0
- Disclosed:
- Dec 30, 2024
CVE-2024-56248 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database