← WordPress Vulnerabilities
WordPress security by component

Unbounce Landing Pages

Unbounce Landing Pages (unbounce) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 08, 2026; the highest published CVSS base score is 7.1.

Plugin slug: unbounce

CVE-2026-81781: Unbounce Landing Pages permits low-privilege access-control abuse

Unbounce Landing Pages through 1.1.4 lacks authorization checks on a plugin operation. The CNA vector requires a low-privilege authenticated attacker, without naming a WordPress role, and rates the consequences as reduced availability and unauthorized modification without victim interaction. WordPress.org still lists 1.1.4 as the latest release.

PublishedSep 08, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for unbounce
Safe version
Sep 08, 2026 CVE-2026-81781
Unbounce Landing Pages permits low-privilege access-control abuse
Unbounce Landing Pages through 1.1.4 lacks authorization checks on a plugin operation. The CNA vector requires a low-privilege authenticated attacker, without naming a WordPress role, and rates the consequences as reduced availability and unauthorized modification without victim interaction. WordPress.org still lists 1.1.4 as the latest release.
See mitigation notes
CVE7.1
NVDPending