CVE-2026-78259: WordPress WPLegalPages plugin <= 3.7.0 - Broken Authentication vulnerability
Published Aug 24, 2026
·Updated
Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions.
Affected Software
1 affected component
WordPress WPLegalPages plugin<=3.7.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WPLegalPages pluginto a version that resolves this vulnerability.Fixed in 3.7.1
Event History
Aug 24, 2026
CVE Published
via MITRE·09:31 PM
Data Sourced
via MITRE·09:31 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which installations are affected?
The affected versions are WPLegalPages 3.7.0 and earlier. The provided data does not identify a fixed version.
2
Does exploitation require an authenticated WordPress account or user interaction?
No. The vulnerability is described as unauthenticated, and the CVSS vector indicates no privileges and no user interaction are required.
3
What level of impact could successful exploitation have?
The supplied CVSS vector rates confidentiality, integrity, and availability impact as low, with network-based access and low attack complexity.