PT-2025-38306 · WordPress · Wordpress+1
Wesley
·
Published
2025-09-18
·
Updated
2025-09-19
·
CVE-2025-8565
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WP Legal Pages plugin for WordPress versions up to and including 3.4.3
Description
The WP Legal Pages plugin for WordPress is susceptible to unauthorized access of functionality due to a missing capability check on the
wplp gdpr install plugin ajax handler() function. This allows authenticated attackers with Contributor-level access or higher to install arbitrary repository plugins.Recommendations
Update WP Legal Pages plugin to a version later than 3.4.3.
As a temporary workaround, restrict access for users with Contributor-level access and above.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wplegalpages
Wordpress