CyberRota Analysis
AI-GeneratedThe Unbounce Landing Pages WordPress plugin prior to version 1.1.5 is vulnerable due to a lack of authorization checks when updating its front-end proxy configuration. This flaw allows any authenticated user, including those with low-level permissions like subscribers, to redirect the proxy to a malicious host, potentially serving arbitrary content from the site's origin. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of unauthorized content manipulation.
Original NVD Description
The Unbounce Landing Pages WordPress plugin before 1.1.5 does not perform any authorisation check when updating the configuration its front-end proxy relies on, allowing any authenticated user, such as a subscriber, to point that proxy at a host they control and have arbitrary content served from the site's own origin.