Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

M.Fahad Khan

#53404of 56,334
4.3Total CVSS
Vulnerabilities · 1
PT-2026-60397
4.3
2026-07-16
WordPress · Landing Page Builder · CVE-2026-12409
**Name of the Vulnerable Software and Affected Versions** Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages versions prior to 1.5.3.7 **Description** Cross-Site Request Forgery occurs due to missing or incorrect nonce validation in the `ulpb admin ajax()` function. This allows unauthenticated attackers to create, update, retitle, or change the post status, slug, and type of arbitrary posts, as well as write `ULPB DATA` post meta through a forged request. The attack requires a victim with editor-level or administrator privileges to perform an action, such as clicking a link, because the `wp ajax ulpb admin data` action requires a capability check satisfied by the logged-in user's session cookies. **Recommendations** Update to version 1.5.3.7 or later.