CVE-2025-66077: WordPress Legal Pages plugin <= 1.4.6 - Broken Access Control vulnerability
Published Nov 21, 2025
·Updated
Missing Authorization vulnerability in wpWax Legal Pages legal-pages allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Legal Pages: from n/a through <= 1.4.6.
Affected Software
2 affected components
wpWax Legal Pages<=1.4.6
WordPress Legal Pages<=1.4.6
Event History
Nov 21, 2025
CVE Published
via MITRE·12:29 PM
Data Sourced
via MITRE·12:29 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-66077?
CVE-2025-66077 is considered a critical vulnerability due to the risk of unauthorized access and exploitation.
2
How do I fix CVE-2025-66077?
To mitigate CVE-2025-66077, update the wpWax Legal Pages plugin to version 1.4.7 or later.
3
What versions are affected by CVE-2025-66077?
CVE-2025-66077 affects wpWax Legal Pages versions from n/a up to and including 1.4.6.
4
What is the nature of the vulnerability in CVE-2025-66077?
CVE-2025-66077 is a missing authorization vulnerability that allows exploitation of incorrectly configured access control security levels.
5
Who is impacted by CVE-2025-66077?
Users of wpWax Legal Pages and WordPress Legal Pages using versions up to 1.4.6 are impacted by CVE-2025-66077.