๐Ÿ” CVE Alert

CVE-2026-85574

UNKNOWN 0.0

Unbounce Landing Pages 1.1.1 - 1.1.4 - Subscriber+ Reverse-Proxy Target Hijack via set_unbounce_domains

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Unbounce Landing Pages WordPress plugin before 1.1.5 does not perform any authorisation check when updating the configuration its front-end proxy relies on, allowing any authenticated user, such as a subscriber, to point that proxy at a host they control and have arbitrary content served from the site's own origin.

Vendor unknown
Product unbounce landing pages
Published Sep 19, 2026
Stay Ahead of the Next One

Get instant alerts for unknown unbounce landing pages

Be the first to know when new unknown vulnerabilities affecting unknown unbounce landing pages are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Unbounce Landing Pages
1.1.1 < 1.1.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/f13143dc-5674-4e9f-8aa0-8d22df7a7379/

Credits

Furkan Arslan WPScan