Junglewise Threat Intelligence

CVE-2026-85574: Unbounce Landing Pages authorization bypass in proxy configuration

CVE-2026-85574 · Severity: high · CVSS 8 · Published 2026-09-19

Executive brief

The Unbounce Landing Pages WordPress plugin fails to verify user permissions when updating the front-end reverse proxy configuration, allowing any logged-in subscriber-level user to redirect the proxy to point at attacker-controlled servers. This enables attackers to serve malicious content through the legitimate site's domain, facilitating credential theft, malware distribution, and other attacks that abuse the site's trusted origin.

Technical details

Missing authorization check (CWE-862) on the set_unbounce_domains functionality allows any authenticated user to modify proxy target configuration without role-based access control. The vulnerability requires user authentication but no elevated privileges, enabling subscriber-level users to hijack the reverse proxy and inject arbitrary content from their own hosts while maintaining the legitimate site's origin in the browser. The vulnerability is fixed in plugin version 1.1.5.

Affected products

  • Unbounce Landing Pages 1.1.1 through 1.1.4

Timeline

  • 2026-09-17: disclosed
  • 2026-09-19: patched: Fixed in version 1.1.5

References

Related threats