Description
Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions.
Published: 2026-08-24
Score: 7.3 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WPLegalPages plugin up to version 3.7.0 contains a flaw that permits attackers to bypass the authentication system without providing valid credentials. By exploiting this weakness, an attacker could obtain the same privileges as an authorized user, potentially viewing or modifying sensitive content, settings, or administrative controls.

Affected Systems

WordPress installations that have the WPLegalPages plugin version 3.7.0 or older are affected. Any site using this plugin in that version range is vulnerable, regardless of other plugins or configurations.

Risk and Exploitability

The flaw is scored CVSS 7.3, indicating high impact. EPSS data is not available and the vulnerability is not listed in CISA KEV, yet the attack vector is unauthenticated and remote: an attacker can craft HTTP requests to plugin endpoints and gain privileges. Because no credentials are required, the risk of exploitation remains significant on exposed WordPress sites.

Generated by OpenCVE AI on August 24, 2026 at 22:27 UTC.

Remediation

Vendor Solution

Update the WordPress WPLegalPages Plugin to the latest available version (at least 3.7.1).


OpenCVE Recommended Actions

  • Update the WPLegalPages plugin to version 3.7.1 or later.
  • Verify that all plugin files and directories reflect the new version and that old version files are removed.
  • If an immediate update is not possible, deactivate the WPLegalPages plugin to prevent exploitation until the patch is applied.

Generated by OpenCVE AI on August 24, 2026 at 22:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions.
Title WordPress WPLegalPages plugin <= 3.7.0 - Broken Authentication vulnerability
Weaknesses CWE-288
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-24T21:31:29.978Z

Reserved: 2026-08-24T07:37:35.411Z

Link: CVE-2026-78259

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-24T22:17:19.803

Modified: 2026-08-24T22:17:19.803

Link: CVE-2026-78259

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T22:30:04Z

Weaknesses
  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel