Junglewise Threat Intelligence

CVE-2026-78259: WPLegalPages broken authentication vulnerability

CVE-2026-78259 · Severity: high · CVSS 7.3 · Published 2026-08-24

Vendors: WPLegalPages.

Executive brief

WPLegalPages is a WordPress plugin used to manage legal document pages on websites. This vulnerability allows attackers to bypass the plugin's login system or impersonate other users without needing their passwords, potentially gaining unauthorized access to sensitive legal documents and site administration functions. Attackers do not need any credentials to exploit this flaw.

Technical details

A broken authentication vulnerability (CWE-287) in WPLegalPages versions 3.7.0 and earlier allows unauthenticated attackers to bypass the authentication mechanism and gain unauthorized access to the application. The vulnerability allows attackers to log in as arbitrary users without knowledge of their passwords. No special network positioning, special configuration, or user interaction is required to exploit this vulnerability. The flaw is exploitable remotely over the network by any unauthenticated user. The vulnerability was patched in version 3.7.1.

Affected products

  • WPLegalPages WPLegalPages <=3.7.0

Timeline

  • 2026-08-24: disclosed
  • 2026-08-24: patched: Patched in version 3.7.1

References