Impact
A missing authorization flaw has been identified in the Unbounce Landing Pages WordPress plugin. The flaw allows exploitation of incorrectly configured access control security levels, enabling an attacker to access plugin functionality for which authorization is normally required.
Affected Systems
The vulnerability impacts the Unbounce Landing Pages plugin for WordPress, affecting all versions up to and including 1.1.4. Every installation running one of these versions is potentially compromised, regardless of the WordPress core version or hosting environment.
Risk and Exploitability
The CVSS score of 7.1 classifies this issue as high severity, indicating a significant potential impact if exploited. The EPSS score is not available, suggesting limited publicly known exploitation activity at the time, and the vulnerability is not listed in the CISA KEV catalog. The attack is likely possible through the plugin’s web interface endpoints, as the flaw stems from missing authorization checks. Consequently, the risk remains moderate to high pending remediation.
OpenCVE Enrichment