OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-85574

HIGH · CVSS 8 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-09-19 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The Unbounce Landing Pages WordPress plugin prior to version 1.1.5 is vulnerable due to a lack of authorization checks when updating its front-end proxy configuration. This flaw allows any authenticated user, including those with low-level permissions like subscribers, to redirect the proxy to a malicious host, potentially serving arbitrary content from the site's origin. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of unauthorized content manipulation.

CVE
CVE-2026-85574
Severity
HIGH
CVSS
8
EPSS
0.34%
WordPress

Original NVD Description

The Unbounce Landing Pages WordPress plugin before 1.1.5 does not perform any authorisation check when updating the configuration its front-end proxy relies on, allowing any authenticated user, such as a subscriber, to point that proxy at a host they control and have arbitrary content served from the site's own origin.