Unauthorized Data Modification in WP Legal Pages Plugin for WordPress
CVE-2025-11816
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 1 November 2025
What is CVE-2025-11816?
The WP Legal Pages WordPress plugin is susceptible to an unauthorized data modification vulnerability due to inadequate capability checks in the disconnect_account_request() function. This flaw affects all versions up to and including 3.5.1, allowing unauthenticated attackers to sever the connection to the site's API plan, potentially leading to data integrity issues and unauthorized actions. It is essential to update the plugin to a secure version to prevent exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages * <= 3.5.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved