ZeroHour

CVE-2026-81781

niche

Missing Authorization in Unbounce Landing Pages WordPress Plugin

CVSS 3.1
7.1 high
EPSS
<1%p8
Published
()
Modified
AI analysis

CVE-2026-81781 is a missing-authorization flaw (CWE-862) in the Unbounce Landing Pages WordPress plugin, where an access-control check on a network-reachable action is absent or incorrectly configured. An attacker who already holds a low-privileged account on an affected site can send a crafted request that the plugin processes without properly verifying the user's permissions. Per the CVSS vector, successful exploitation produces limited integrity impact and high availability impact, with no confidentiality impact. Any WordPress site running Unbounce Landing Pages versions through 1.1.4 is affected. No public proof-of-concept or in-the-wild exploitation is currently known; EPSS is 0.2% (8th percentile) and the CVE is not in CISA KEV.

What to do: Upgrade the plugin to the first release after 1.1.4 as soon as one is available (the patched version number is not given in the source data), and check Dashboard > Plugins to confirm your installed version. Until patched, audit which low-privileged users (e.g., subscribers/contributors) have accounts on affected sites and disable the plugin if it is not actively used. No public PoC exists, so routine patching cadence is reasonable given the low EPSS score.

Affected
Unbounce Landing Pages (WordPress plugin)
Estimated exposure
nicheon the order of a few thousand to ~10,000 WordPress sites (specialized connector plugin; exact active-install count not in source data) — The Unbounce connector is a niche WordPress.org plugin used only where publishers serve Unbounce landing pages through WordPress, so its install base is far smaller than typical marketing plugins; the estimate is an order-of-magnitude…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Missing Authorization vulnerability in Unbounce Unbounce Landing Pages unbounce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Unbounce Landing Pages: from n/a through 1.1.4.

Ecosystems
WordPress
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H

In the news

No ingested article mentions this CVE yet.