Sceawere

Vulnerability Detail

CVE-2026-78259UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

WPLegalPages Broken Authentication Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.3
Creation Date
3h ago
Vendor
WP Legal Pages
Product
WPLegalPages
Attack Type
CWE-288 Authentication Bypass Using an Alternate Path or Channel
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.3",
  "pubDate": "2026-08-24T22:17:19.803Z",
  "pubdate": "2026-08-24T22:17:19.803Z",
  "executiveSummary": "An unauthenticated broken authentication vulnerability has been identified in the WPLegalPages plugin affecting versions 3.7.0 and below. This security flaw allows unauthenticated remote adversaries to bypass standard access controls and authentication mechanisms implemented within the affected software components.\nThe primary impact of this vulnerability is the potential unauthorized access to restricted functionalities or sensitive data managed by the plugin, severely undermining the integrity and confidentiality of the underlying WordPress installation. The risk implications are critical, as exploitation requires no prior authentication or specialized privileges, lowering the barrier to entry for malicious actors.\nAttackers targeting this vulnerability do not need valid credentials to initiate exploitation, relying solely on network exposure to interact with the vulnerable endpoints. Remediation requires immediate attention from system administrators, specifically through applying vendor-supplied patches or upgrading to a secure version beyond 3.7.0 once available.",
  "technicalDetails": "The root cause of this vulnerability lies in the flawed implementation of session validation and access control checks within the authentication handling logic of the WPLegalPages plugin for versions 3.7.0 and prior. Specifically, the vulnerable component fails to properly verify whether an incoming request originates from an authenticated and authorized user before granting access to sensitive administrative or functional endpoints.\nThe attack vector is network-based, exposing the application to unauthenticated remote exploitation. Because the affected code paths lack rigorous authentication enforcement, an adversary can directly issue HTTP requests to specific vulnerable plugin endpoints without supplying valid session tokens, cookies, or cryptographic credentials.\nThe step-by-step attack flow proceeds as follows: First, the unauthenticated actor identifies the target WordPress instance running a vulnerable version of the WPLegalPages plugin. Second, the attacker crafts a targeted HTTP request directed toward the unprotected or improperly guarded function handler. Third, due to the absence of adequate input validation and session verification routines, the backend application processes the request as if it originated from a legitimate, authenticated user.\nConsequently, the payload behavior allows the adversary to bypass access controls entirely, executing privileged actions or retrieving restricted data associated with the plugin's operational scope. The post-exploitation impact includes unauthorized modification of legal pages, potential exposure of sensitive configuration data, and further compromise of the WordPress environment depending on the privileges inadvertently granted by the flawed authorization boundary."
}
CVE-2026-78259: WPLegalPages Broken Authentication Vulnerability (HIGH Severity, CVSS: 7.3) - Sceawere