{"id":"CVE-2026-85574","published":"2026-09-19T07:16:32.860","lastModified":"2026-09-21T13:34:57.127","description":"The Unbounce Landing Pages WordPress plugin before 1.1.5 does not perform any authorisation check when updating the configuration its front-end proxy relies on, allowing any authenticated user, such as a subscriber, to point that proxy at a host they control and have arbitrary content served from the site's own origin.","cvssScore":8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","cwes":["CWE-862"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/f13143dc-5674-4e9f-8aa0-8d22df7a7379/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}