Description
Kupu 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, and 4.2.0 through 4.2.7 allows remote authenticated users to edit Kupu settings.
Remediation
References
Related Vulnerabilities
Chamilo Session Fixation Vulnerability (CVE-2026-31940)
WordPress Plugin Media File Renamer-Auto & Manual Rename Cross-Site Request Forgery (5.2.5)
WordPress Plugin Forminator-Contact Form, Payment Form & Custom Form Builder SQL Injection (1.29.2)
WordPress Plugin Downloads Manager 'upload.php' Arbitrary File Upload (0.2)