Impact
The WPLegalPages plugin up to version 3.7.0 contains a flaw that permits attackers to bypass the authentication system without providing valid credentials. By exploiting this weakness, an attacker could obtain the same privileges as an authorized user, potentially viewing or modifying sensitive content, settings, or administrative controls.
Affected Systems
WordPress installations that have the WPLegalPages plugin version 3.7.0 or older are affected. Any site using this plugin in that version range is vulnerable, regardless of other plugins or configurations.
Risk and Exploitability
The flaw is scored CVSS 7.3, indicating high impact. EPSS data is not available and the vulnerability is not listed in CISA KEV, yet the attack vector is unauthenticated and remote: an attacker can craft HTTP requests to plugin endpoints and gain privileges. Because no credentials are required, the risk of exploitation remains significant on exposed WordPress sites.
OpenCVE Enrichment