← WordPress Vulnerabilities
WordPress security by component

'The Ultimate WordPress Toolkit – WP Extended'

'The Ultimate WordPress Toolkit – WP Extended' is a WordPress component with 15 published CVE records in this archive. The latest tracked vulnerability was published Mar 22, 2026; the highest CVE/CNA score is 8.8.

Plugin slug: wpextended

CVE-2026-4314: 'The Ultimate WordPress Toolkit – WP Extended': Privilege escalation or authentication bypass

'The Ultimate WordPress Toolkit – WP Extended' is affected by privilege escalation or authentication bypass. Exploitation requires at least subscriber-level access. A successful request can grant permissions or access that the caller should not possess.

PublishedMar 22, 2026
Safe version guidanceSee mitigation notes
Safe version
Mar 22, 2026 CVE-2026-4314
'The Ultimate WordPress Toolkit – WP Extended': Privilege escalation or authentication bypass
'The Ultimate WordPress Toolkit – WP Extended' is affected by privilege escalation or authentication bypass. Exploitation requires at least subscriber-level access. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.8
NVDPending
May 28, 2025 CVE-2025-4963
WP Extended: Cross-site scripting
WP Extended is affected by cross-site scripting. Exploitation requires at least author-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Apr 01, 2025 CVE-2025-30796
The Ultimate WordPress Toolkit – WP Extended: Cross-site scripting
The Ultimate WordPress Toolkit – WP Extended is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVDPending
Jan 18, 2025 CVE-2024-13184
The Ultimate WordPress Toolkit – WP Extended: SQL injection
The Ultimate WordPress Toolkit – WP Extended is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.5
NVDPending
Jan 08, 2025 CVE-2024-11816
Ultimate WordPress Toolkit – WP Extended: Code execution
Ultimate WordPress Toolkit – WP Extended is affected by code execution. Exploitation requires at least subscriber-level access. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE8.8
NVDPending
Oct 17, 2024 CVE-2024-9347
The Ultimate WordPress Toolkit – WP Extended: Cross-site scripting
The Ultimate WordPress Toolkit – WP Extended is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending
Oct 05, 2024 CVE-2024-47386
The Ultimate WordPress Toolkit – WP Extended: Cross-site scripting
The Ultimate WordPress Toolkit – WP Extended is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVDPending
Sep 04, 2024 CVE-2024-8123
The Ultimate WordPress Toolkit – WP Extended: A security weakness
The Ultimate WordPress Toolkit – WP Extended is affected by a security weakness. Exploitation requires at least contributor-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVD5.4
Sep 04, 2024 CVE-2024-8121
The Ultimate WordPress Toolkit – WP Extended: A security weakness
The Ultimate WordPress Toolkit – WP Extended is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVD4.3
Sep 04, 2024 CVE-2024-8119
The Ultimate WordPress Toolkit – WP Extended: Cross-site scripting
The Ultimate WordPress Toolkit – WP Extended is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending
Sep 04, 2024 CVE-2024-8117
The Ultimate WordPress Toolkit – WP Extended: Cross-site scripting
The Ultimate WordPress Toolkit – WP Extended is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending
Sep 04, 2024 CVE-2024-8106
The Ultimate WordPress Toolkit – WP Extended: Sensitive information exposure
The Ultimate WordPress Toolkit – WP Extended is affected by sensitive information exposure. Exploitation requires at least subscriber-level access. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE6.5
NVDPending
Sep 04, 2024 CVE-2024-8104
The Ultimate WordPress Toolkit – WP Extended: Filesystem traversal
The Ultimate WordPress Toolkit – WP Extended is affected by filesystem traversal. Exploitation requires an authenticated WordPress account. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE8.8
NVD6.5
Sep 04, 2024 CVE-2024-8102
The Ultimate WordPress Toolkit – WP Extended: Privilege escalation or authentication bypass
The Ultimate WordPress Toolkit – WP Extended is affected by privilege escalation or authentication bypass. Exploitation requires at least subscriber-level access. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.8
NVDPending
Jul 22, 2024 CVE-2024-37259
The Ultimate WordPress Toolkit – WP Extended: Cross-site scripting
The Ultimate WordPress Toolkit – WP Extended is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1