๐Ÿ” CVE Alert

CVE-2026-16984

MEDIUM 6.5

WP Legal Pages < 3.7.1 - Unauthenticated API Secret Disclosure

CVSS Score
6.5
EPSS Score
0.2%
EPSS Percentile
7th

The Privacy Policy Generator, Terms & Conditions, GDPR, CCPA, Cookie Policy & Disclaimer Templates WordPress plugin before 3.7.1 does not include an authorization check on a REST route that returns stored account data, allowing unauthenticated visitors to retrieve the connected service's API secret and account details, which can then be used to disconnect the Privacy Policy Generator, Terms & Conditions, GDPR, CCPA, Cookie Policy & Disclaimer Templates WordPress plugin before 3.7.1's integration.

Vendor unknown
Product privacy policy generator, terms & conditions, gdpr, ccpa, cookie policy & disclaimer templates
Published Aug 26, 2026
Last Updated Aug 26, 2026
Stay Ahead of the Next One

Get instant alerts for unknown privacy policy generator, terms & conditions, gdpr, ccpa, cookie policy & disclaimer templates

Be the first to know when new medium vulnerabilities affecting unknown privacy policy generator, terms & conditions, gdpr, ccpa, cookie policy & disclaimer templates are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Privacy Policy Generator, Terms & Conditions, GDPR, CCPA, Cookie Policy & Disclaimer Templates
0 < 3.7.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/c1bf0335-c954-473b-af30-7f227f041790/

Credits

Vaibhav Narkhede WPScan