PT-2025-44696 · WordPress · Wordpress+1

·

CVE-2025-11816

·

Published

2025-11-01

·

Updated

2025-11-15

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions WP Legal Pages versions prior to 3.5.2
Description The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin: WP Legal Pages is susceptible to unauthorized data modification. This is due to a missing capability check within the disconnect account request() function. This allows unauthenticated attackers to disconnect a site from its API plan.
Recommendations WP Legal Pages versions prior to 3.5.2 should be updated.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-11816

Affected Products

Wplegalpages
Wordpress