CVE-2026-2294 | admintwentytwenty UiPress lite Plugin up to 3.5.09 on WordPress Setting uip_save_global_settings improper authorization
A vulnerability was found in admintwentytwenty UiPress lite Plugin up to 3.5.09 on WordPress and classified as critical. This impacts the function uip_save_global_settings of the component Setting Handler. Executing a manipulation can lead to improper authorization.
The identification of this vulnerability is CVE-2026-2294. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.