PT-2026-95756 · WordPress · Unbounce Landing Pages
CVSS v3.1
8.0
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Unbounce Landing Pages WordPress plugin versions prior to 1.1.5
Description
An authorization bypass exists when updating the configuration used by the front-end proxy. This allows any authenticated user, including those with subscriber-level privileges, to redirect the proxy to a host under their control, enabling the delivery of arbitrary content from the site's own origin.
Recommendations
Update the Unbounce Landing Pages WordPress plugin to version 1.1.5 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Unbounce Landing Pages