Description
The Unbounce Landing Pages WordPress plugin before 1.1.5 does not perform any authorisation check when updating the configuration its front-end proxy relies on, allowing any authenticated user, such as a subscriber, to point that proxy at a host they control and have arbitrary content served from the site's own origin.
Published: 2026-09-19
Score: 8 High
EPSS: < 1% Very Low
KEV: No
Impact: Unrestricted reverse proxy configuration leading to arbitrary content serving
Action: Patch immediately
AI Analysis

Impact

The plugin fails to verify that only privileged users can modify its front‑end proxy settings. Any authenticated user, such as a subscriber, can change the proxy target URL to point at a host they control. Once set, the site serves content from the attacker’s host under its own domain, facilitating phishing, malware delivery, or other forms of content spoofing. This flaw does not grant code execution or database access but enables a malicious actor to replace legitimate pages with malicious ones from a perspective of a legitimate user.

Affected Systems

Unbounce Landing Pages WordPress plugin versions 1.1.1 through 1.1.4 are affected. All installations using these versions are vulnerable until updated beyond 1.1.5.

Risk and Exploitability

Exploit requires only an authenticated session, which most visitors can obtain by logging in or by compromising a user account. The flaw is a straightforward POST or configuration change in the plugin, with no additional technical barriers. The EPSS score is < 1% and the CVSS score is 8.0, indicating high severity. Even though exploitation is unlikely according to EPSS, the vulnerability is not tracked in CISA KEV, its potential to undermine site trust and deliver malicious content gives it moderate to high impact, and the lack of access control makes it low effort to exploit.

Generated by OpenCVE AI on September 20, 2026 at 01:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Unbounce Landing Pages plugin version 1.1.5 or later, which fixes the authorization check.
  • Restrict access to the set_unbounce_domains configuration option so that only administrator roles can change it, using a role‑based permissions plugin or the plugin’s own settings.
  • Continuously monitor the proxy configuration for unexpected changes and enable audit logging to detect illicit modifications.

Generated by OpenCVE AI on September 20, 2026 at 01:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress-extensions
Wordpress-extensions unbounce Landing Pages
Vendors & Products Wordpress-extensions
Wordpress-extensions unbounce Landing Pages

Sun, 20 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 8.0, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}


Sat, 19 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Sat, 19 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Unbounce Landing Pages WordPress plugin before 1.1.5 does not perform any authorisation check when updating the configuration its front-end proxy relies on, allowing any authenticated user, such as a subscriber, to point that proxy at a host they control and have arbitrary content served from the site's own origin.
Title Unbounce Landing Pages 1.1.1 - 1.1.4 - Subscriber+ Reverse-Proxy Target Hijack via set_unbounce_domains
References

Subscriptions

Wordpress-extensions Unbounce Landing Pages
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-19T13:19:55.664Z

Reserved: 2026-09-04T10:54:30.600Z

Link: CVE-2026-85574

cve-icon Vulnrichment

Updated: 2026-09-19T13:13:01.448Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T07:16:32.860

Modified: 2026-09-21T13:34:57.127

Link: CVE-2026-85574

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T19:49:34Z

Weaknesses