Impact
The Landing Page Builder plugin for WordPress, developed by umarbajwa, contains a flaw in its ulpb_admin_ajax function where nonce validation is missing or incorrect. This allows an unauthenticated attacker to forge a request to the wp_ajax_ulpb_admin_data endpoint and, if a logged‑in editor or administrator clicks on a crafted link or submits a malicious form, create, update, or delete posts, change their status, slug, or type, and write arbitrary ULPB_DATA post meta. The effect is unauthorized modification of site content that can undermine site integrity and trust.
Affected Systems
All releases of the Landing Page Builder plugin up through and including version 1.5.3.6 are affected. Sites running any of these versions—such as 1.5.3.5 or 1.5.3.6—must be considered vulnerable.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity while the EPSS score of less than 1 % reflects a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers must rely on a logged‑in administrator or editor to execute the forged request, so the attack vector is typically a social‑engineering click on a malicious link. Although the potential impact on site content is significant, the realistic risk remains limited by the requirement for user interaction and an authenticated session.
OpenCVE Enrichment