Medium 4.4
2025-12-13< 1.18.2
CVE-2025-14056
Minimum safe version
1.18.2
Update to 1.18.2 or later to address 7 fixable vulnerabilities
CVE-2025-14056
CVE-2025-12826
WordPress Custom Post Type UI Plugin < 1.13.5 is vulnerable to Cross Site Request Forgery (CSRF)
WordPress Custom Post Type UI Plugin <= 1.13.4 is vulnerable to Cross Site Request Forgery (CSRF)
Custom Post Type UI <= 1.7.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Custom Post Type UI < 1.7.4 - CSRF to Stored XSS
WordPress Custom Post Type UI plugin <= 1.7.3 - Cross-Site Request Forgery (CSRF) vulnerability leading to Stored Cross-Site Scripting (XSS)