Unauthenticated Authentication Flaw in WPLegalPages by WordPress
CVE-2026-78259
7.3HIGH
What is CVE-2026-78259?
A significant security concern in the WPLegalPages plugin for WordPress allows unauthenticated users to exploit broken authentication mechanisms. This vulnerability, present in versions 3.7.0 and below, could potentially enable malicious actors to gain unauthorized access and manipulate sensitive features within the plugin, jeopardizing the integrity of user data and privacy. It is crucial for users and administrators to update to the latest version to mitigate this risk.
Affected Version(s)
WPLegalPages <= 3.7.0