
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1103 is a Missing Authorization vulnerability in the AIKTP plugin for WordPress, classified under CWE-862. It affects all versions of the plugin up to and including 5.0.04, allowing authenticated attackers with Subscriber-level access or above to retrieve the administrator's aiktpz_token access token via the /aiktp/getToken REST API endpoint. The vulnerability was disclosed on January 24, 2026, with Wordfence as the reporting CNA. It carries a CVSS v3.1 base score of 5.4 (Medium) (Wordfence, Red Hat CVE).
The root cause is a missing authorization check (CWE-862) on the /aiktp/getToken REST API endpoint. The endpoint uses verify_user_logged_in as its permission callback, which only confirms that a user is authenticated but does not verify whether the user holds administrative capabilities. As a result, any authenticated user — including those with the lowest Subscriber role — can call this endpoint and retrieve the administrator's aiktpz_token. The vulnerable logic is visible in the plugin source at aiktp-sync.php lines 123 and 143 (WordPress Plugin Trac, Wordfence).
Successful exploitation allows an attacker to obtain the administrator's aiktpz_token, which can then be used to create posts, upload files to the media library, and access private content as the administrator. This results in low-level confidentiality and integrity impacts — private content may be exposed and unauthorized content may be published or uploaded — though availability is not directly affected. The scope is limited to the WordPress site running the vulnerable plugin, but the ability to act as an administrator could facilitate further abuse such as uploading malicious files or defacing site content (Wordfence).
Exploitation requires only a valid low-privileged (Subscriber-level) account on the target WordPress site, making it accessible to any registered user. No public exploit code or active in-the-wild exploitation has been reported as of the available data. The EPSS score is approximately 0.026%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Feedly, Wordfence).
/wp-content/plugins/aiktp/readme.txt./wp-json/aiktp/getToken REST API endpoint using the session cookie or application password of the low-privileged account.aiktpz_token value belonging to the administrator.aiktpz_token to perform privileged actions such as creating posts, uploading files to the media library, or accessing private content as the administrator (Wordfence, WordPress Plugin Trac)./wp-json/aiktp/getToken from non-administrative user accounts; repeated calls to this endpoint from the same IP or user session./wp-json/aiktp/getToken by Subscriber-level users; unexpected content creation or media uploads attributed to the administrator account following such requests./wp-content/uploads/) that do not correspond to administrator activity.Users should update the AIKTP plugin to a version beyond 5.0.04 that includes a proper authorization check on the /aiktp/getToken endpoint. The patch changeset is available in the WordPress Plugin SVN repository (WordPress Plugin Changeset). As an interim workaround, site administrators can restrict user registration or remove Subscriber-level accounts if they are not required, and monitor REST API access logs for suspicious calls to the affected endpoint. Disabling the AIKTP plugin entirely until a patched version is confirmed deployed is also a viable temporary measure.
Wordfence, the discovering and reporting organization, published the vulnerability details in their threat intelligence database (Wordfence). The vulnerability was also noted by InfinitSec in a brief post summarizing the issue (InfinitSec). No significant broader media coverage or notable researcher commentary beyond standard vulnerability aggregation has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."