CVE-2026-81781
nicheMissing Authorization in Unbounce Landing Pages WordPress Plugin
CVE-2026-81781 is a missing-authorization flaw (CWE-862) in the Unbounce Landing Pages WordPress plugin, where an access-control check on a network-reachable action is absent or incorrectly configured. An attacker who already holds a low-privileged account on an affected site can send a crafted request that the plugin processes without properly verifying the user's permissions. Per the CVSS vector, successful exploitation produces limited integrity impact and high availability impact, with no confidentiality impact. Any WordPress site running Unbounce Landing Pages versions through 1.1.4 is affected. No public proof-of-concept or in-the-wild exploitation is currently known; EPSS is 0.2% (8th percentile) and the CVE is not in CISA KEV.
What to do: Upgrade the plugin to the first release after 1.1.4 as soon as one is available (the patched version number is not given in the source data), and check Dashboard > Plugins to confirm your installed version. Until patched, audit which low-privileged users (e.g., subscribers/contributors) have accounts on affected sites and disable the plugin if it is not actively used. No public PoC exists, so routine patching cadence is reasonable given the low EPSS score.
| Unbounce Landing Pages (WordPress plugin) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Missing Authorization vulnerability in Unbounce Unbounce Landing Pages unbounce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Unbounce Landing Pages: from n/a through 1.1.4.
- Ecosystems
- WordPress
- Weakness
- CWE-862
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
In the news0 stories
No ingested article mentions this CVE yet.