{"id":"CVE-2026-85574","title":"The Unbounce Landing Pages WordPress plugin before 1.1.5 does not perform any authorisation check when updating the configuration its front-end proxy relies on, allowing any authenticated user, such as a subscriber, to point that proxy a…","summary":"The Unbounce Landing Pages WordPress plugin before 1.1.5 does not perform any authorisation check when updating the configuration its front-end proxy relies on, allowing any authenticated user, such as a subscriber, to point that proxy a…","severity":"high","cvss":8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-862"],"product":"Unbounce Landing Pages","affected":["unbounce_landing_pages >= 1.1.1 < 1.1.5"],"published":"2026-09-19","updated":"2026-09-21","sourceUpdated":"2026-09-21T13:34:57.127","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-85574","references":[{"url":"https://wpscan.com/vulnerability/f13143dc-5674-4e9f-8aa0-8d22df7a7379/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"epss":0.00187,"epssPercentile":0.08509,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-19T13:14:51.627789Z"},"ingestedAt":"2026-09-19T06:59:13.116Z","slug":"CVE-2026-85574","body":"## Overview\n\nThe Unbounce Landing Pages WordPress plugin before 1.1.5 does not perform any authorisation check when updating the configuration its front-end proxy relies on, allowing any authenticated user, such as a subscriber, to point that proxy at a host they control and have arbitrary content served from the site's own origin.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":44,"depthScoreParts":{"impact":44,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":207698,"id":"CVE-2026-85574","ts":1789826663632,"field":"cvss","old":null,"new":"8"},{"seq":207697,"id":"CVE-2026-85574","ts":1789826663632,"field":"severity","old":"none","new":"high"}]}