Missing Authorization Vulnerability in WP Legal Pages by WordPress
CVE-2025-67974
7.5HIGH
What is CVE-2025-67974?
A missing authorization vulnerability has been identified in the WP Legal Pages plugin. This flaw arises due to incorrectly configured access control security levels, which can allow unauthorized access to sensitive areas of the plugin functionalities. Affected versions of WPLegalPages are all prior to version 3.5.4. It is crucial for users to evaluate their configurations and update the plugin to mitigate the risk of exploitation.
Affected Version(s)
WPLegalPages 0 <= 3.5.4