Junglewise Threat Intelligence

CVE-2026-81781: Unbounce Landing Pages broken access control in plugin

CVE-2026-81781 · Severity: high · CVSS 7.1 · Published 2026-09-08

Executive brief

The Unbounce Landing Pages WordPress plugin allows users to create and manage landing pages on WordPress websites. A broken access control vulnerability permits subscribers and other lower-privilege users to access landing pages and perform actions they should not have permission for, such as viewing or modifying pages belonging to other users. This could expose confidential campaign data, customer information, or allow unauthorized modifications to published landing pages.

Technical details

This is a broken access control (OWASP A01:2021) vulnerability in the Unbounce Landing Pages WordPress plugin versions up to and including 1.1.4. The vulnerability allows authenticated users with subscriber-level privileges to bypass intended authorization checks and access or modify landing pages they should not have permission to interact with. The attack requires user authentication but no special network positioning; any subscriber account can exploit this. An attacker can view other users' landing pages, access sensitive campaign data, or modify page content. The vulnerability was patched in version 1.1.5, released in September 2026.

Affected products

  • Unbounce Landing Pages through 1.1.4

Timeline

  • 2026-09-07: disclosed: Published by Patchstack
  • 2026-09-07: patched: Fixed in version 1.1.5

References

Related threats