Medium 6.4
2026-03-25< 4.0.22
CVE-2026-24362
Minimum safe version
4.0.22
Update to 4.0.22 or later to address 8 fixable vulnerabilities
CVE-2026-24362
CVE-2025-14434
Freemius SDK <= 2.4.2 - Missing Authorization Checks
CVE-2024-5662
WordPress Ultimate Post Kit – Addons For Elementor Plugin <= 3.6.3 is vulnerable to Cross Site Scripting (XSS)
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress Ultimate Post Kit – Addons For Elementor plugin < 2.9.1 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability
WordPress Ultimate Post Kit – Addons For Elementor plugin < 2.9.1 - Sensitive Information Disclosure vulnerability