Unauthorized Data Modification in WP Legal Pages Plugin for WordPress
CVE-2025-11816 
5.3MEDIUM
Key Information:
- Vendor
 WordPress
- Vendor
 - CVE Published:
 - 1 November 2025
 
What is CVE-2025-11816?
The WP Legal Pages WordPress plugin is susceptible to an unauthorized data modification vulnerability due to inadequate capability checks in the disconnect_account_request() function. This flaw affects all versions up to and including 3.5.1, allowing unauthenticated attackers to sever the connection to the site's API plan, potentially leading to data integrity issues and unauthorized actions. It is essential to update the plugin to a secure version to prevent exploitation.
Affected Version(s)
Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages * <= 3.5.1