Description
The Unbounce Landing Pages WordPress plugin before 1.1.5 does not perform any authorisation check when updating the configuration its front-end proxy relies on, allowing any authenticated user, such as a subscriber, to point that proxy at a host they control and have arbitrary content served from the site's own origin.
Published: 2026-09-19
Score: 8.0 High
EPSS: < 1% Very Low
KEV: No
Impact: Unrestricted reverse proxy configuration leading to arbitrary content serving
Action: Patch immediately
AI Analysis

Impact

The plugin fails to verify that only privileged users can modify its front‑end proxy settings. Any authenticated user, such as a subscriber, can change the proxy target URL to point at a host they control. Once set, the site serves content from the attacker’s host under its own domain, facilitating phishing, malware delivery, or other forms of content spoofing. This flaw does not grant code execution or database access but enables a malicious actor to replace legitimate pages with malicious ones from a perspective of a legitimate user.

Affected Systems

Unbounce Landing Pages WordPress plugin versions 1.1.1 through 1.1.4 are affected. All installations using these versions are vulnerable until updated beyond 1.1.5.

Risk and Exploitability

Exploit requires only an authenticated session, which most visitors can obtain by logging in or by compromising a user account. The flaw is a straightforward POST or configuration change in the plugin, with no additional technical barriers. While EPSS is not available and the vulnerability is not tracked in CISA KEV, its potential to undermine site trust and deliver malicious content gives it moderate to high impact, and the lack of access control makes it low effort to exploit.

Generated by OpenCVE AI on September 19, 2026 at 10:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Unbounce Landing Pages plugin version 1.1.5 or later, which fixes the authorization check.
  • Restrict access to the set_unbounce_domains configuration option so that only administrator roles can change it, using a role‑based permissions plugin or the plugin’s own settings.
  • Continuously monitor the proxy configuration for unexpected changes and enable audit logging to detect illicit modifications.

Generated by OpenCVE AI on September 19, 2026 at 10:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 8.0, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}


Sat, 19 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Sat, 19 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Unbounce Landing Pages WordPress plugin before 1.1.5 does not perform any authorisation check when updating the configuration its front-end proxy relies on, allowing any authenticated user, such as a subscriber, to point that proxy at a host they control and have arbitrary content served from the site's own origin.
Title Unbounce Landing Pages 1.1.1 - 1.1.4 - Subscriber+ Reverse-Proxy Target Hijack via set_unbounce_domains
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-19T13:19:55.664Z

Reserved: 2026-09-04T10:54:30.600Z

Link: CVE-2026-85574

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-19T07:16:32.860

Modified: 2026-09-19T14:17:00.477

Link: CVE-2026-85574

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T10:15:16Z

Weaknesses