CVE-2026-4314 | wpextended The Ultimate WordPress Toolkit Plugin up to 3.2.4 on WordPress Menu Editor isDashboardOrProfileRequest $_SERVER['REQUEST_URI'] privileges management (EUVD-2026-14275)
A vulnerability was found in wpextended The Ultimate WordPress Toolkit Plugin up to 3.2.4 on WordPress. It has been declared as critical. Affected by this issue is the function isDashboardOrProfileRequest of the component Menu Editor Module. The manipulation of the argument $_SERVER['REQUEST_URI'] results in improper privilege management.
This vulnerability is identified as CVE-2026-4314. The attack can be executed remotely. There is not any exploit available.