CVE-2026-16984: WP Legal Pages < 3.7.1 - Unauthenticated API Secret Disclosure
The Privacy Policy Generator, Terms & Conditions, GDPR, CCPA, Cookie Policy & Disclaimer Templates WordPress plugin before 3.7.1 does not include an authorization check on a REST route that returns stored account data, allowing unauthenticated visitors to retrieve the connected service's API secret and account details, which can then be used to disconnect the Privacy Policy Generator, Terms & Conditions, GDPR, CCPA, Cookie Policy & Disclaimer Templates WordPress plugin before 3.7.1's integration.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any unauthenticated visitor who can reach the affected plugin's REST route can retrieve the stored connected-service API secret and account details. No WordPress account or other authorization is required.
What could an attacker do with the disclosed information?
The disclosed API secret and account details can be used to disconnect the plugin's connected-service integration. The provided information does not describe additional impacts beyond disclosure of the account data and disruption of that integration.
Are installations running version 3.7.1 affected?
No. The issue affects WP Legal Pages versions before 3.7.1; version 3.7.1 is not identified as affected.