Impact
The plugin fails to verify that only privileged users can modify its front‑end proxy settings. Any authenticated user, such as a subscriber, can change the proxy target URL to point at a host they control. Once set, the site serves content from the attacker’s host under its own domain, facilitating phishing, malware delivery, or other forms of content spoofing. This flaw does not grant code execution or database access but enables a malicious actor to replace legitimate pages with malicious ones from a perspective of a legitimate user.
Affected Systems
Unbounce Landing Pages WordPress plugin versions 1.1.1 through 1.1.4 are affected. All installations using these versions are vulnerable until updated beyond 1.1.5.
Risk and Exploitability
Exploit requires only an authenticated session, which most visitors can obtain by logging in or by compromising a user account. The flaw is a straightforward POST or configuration change in the plugin, with no additional technical barriers. While EPSS is not available and the vulnerability is not tracked in CISA KEV, its potential to undermine site trust and deliver malicious content gives it moderate to high impact, and the lack of access control makes it low effort to exploit.
OpenCVE Enrichment