CVE-2026-1103: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-1103 is a Missing Authorization vulnerability in the AIKTP plugin for WordPress, classified under CWE-862. It affects all versions of the plugin up to and including 5.0.04, allowing authenticated attackers with Subscriber-level access or above to retrieve the administrator's aiktpz_token access token via the /aiktp/getToken REST API endpoint. The vulnerability was disclosed on January 24, 2026, with Wordfence as the reporting CNA. It carries a CVSS v3.1 base score of 5.4 (Medium) (Wordfence, Red Hat CVE).

Technical details

The root cause is a missing authorization check (CWE-862) on the /aiktp/getToken REST API endpoint. The endpoint uses verify_user_logged_in as its permission callback, which only confirms that a user is authenticated but does not verify whether the user holds administrative capabilities. As a result, any authenticated user — including those with the lowest Subscriber role — can call this endpoint and retrieve the administrator's aiktpz_token. The vulnerable logic is visible in the plugin source at aiktp-sync.php lines 123 and 143 (WordPress Plugin Trac, Wordfence).

Impact

Successful exploitation allows an attacker to obtain the administrator's aiktpz_token, which can then be used to create posts, upload files to the media library, and access private content as the administrator. This results in low-level confidentiality and integrity impacts — private content may be exposed and unauthorized content may be published or uploaded — though availability is not directly affected. The scope is limited to the WordPress site running the vulnerable plugin, but the ability to act as an administrator could facilitate further abuse such as uploading malicious files or defacing site content (Wordfence).

Exploitability

Exploitation requires only a valid low-privileged (Subscriber-level) account on the target WordPress site, making it accessible to any registered user. No public exploit code or active in-the-wild exploitation has been reported as of the available data. The EPSS score is approximately 0.026%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Feedly, Wordfence).

Exploitation steps

  1. Reconnaissance: Identify a WordPress site running the AIKTP plugin version 5.0.04 or earlier. This can be done by checking the plugin's readme or version file at /wp-content/plugins/aiktp/readme.txt.
  2. Obtain a low-privileged account: Register or log in as a Subscriber-level (or higher) user on the target WordPress site.
  3. Call the vulnerable endpoint: Send an authenticated HTTP GET or POST request to the /wp-json/aiktp/getToken REST API endpoint using the session cookie or application password of the low-privileged account.
  4. Extract the admin token: Parse the API response to retrieve the aiktpz_token value belonging to the administrator.
  5. Abuse the token: Use the retrieved aiktpz_token to perform privileged actions such as creating posts, uploading files to the media library, or accessing private content as the administrator (Wordfence, WordPress Plugin Trac).

Indicators of compromise

  • Network: Unusual authenticated REST API requests to /wp-json/aiktp/getToken from non-administrative user accounts; repeated calls to this endpoint from the same IP or user session.
  • Logs: WordPress access logs showing requests to /wp-json/aiktp/getToken by Subscriber-level users; unexpected content creation or media uploads attributed to the administrator account following such requests.
  • File System: Unexpected files uploaded to the WordPress media library (/wp-content/uploads/) that do not correspond to administrator activity.
  • Application: New posts or pages created under the administrator's authorship that were not initiated by the administrator; access to private posts or pages from non-administrative sessions.

Mitigation and workarounds

Users should update the AIKTP plugin to a version beyond 5.0.04 that includes a proper authorization check on the /aiktp/getToken endpoint. The patch changeset is available in the WordPress Plugin SVN repository (WordPress Plugin Changeset). As an interim workaround, site administrators can restrict user registration or remove Subscriber-level accounts if they are not required, and monitor REST API access logs for suspicious calls to the affected endpoint. Disabling the AIKTP plugin entirely until a patched version is confirmed deployed is also a viable temporary measure.

Community reactions

Wordfence, the discovering and reporting organization, published the vulnerability details in their threat intelligence database (Wordfence). The vulnerability was also noted by InfinitSec in a brief post summarizing the issue (InfinitSec). No significant broader media coverage or notable researcher commentary beyond standard vulnerability aggregation has been observed.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management