CVE-2026-85574: Unbounce Landing Pages 1.1.1 - 1.1.4 - Subscriber+ Reverse-Proxy Target Hijack via set_unbounce_domains
The Unbounce Landing Pages WordPress plugin before 1.1.5 does not perform any authorisation check when updating the configuration its front-end proxy relies on, allowing any authenticated user, such as a subscriber, to point that proxy at a host they control and have arbitrary content served from the site's own origin.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Unbounce Landing Pages WordPress pluginto a version that resolves this vulnerability.Fixed in 1.1.5 - Compensating control
Restrict which users can update Unbounce Landing Pages configuration (e.g., limit to administrators) to prevent authenticated users (such as subscribers) from hijacking the front-end reverse-proxy target via set_unbounce_domains in Unbounce Landing Pages 1.1.1 - 1.1.4.
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated WordPress user can exploit it, including users with only the Subscriber role. No elevated WordPress administrative capability is required.
What does an attacker need to do to exploit it?
The attacker needs a valid authenticated account on the affected WordPress site and control of a host they can configure as the proxy target. They can then change the front-end proxy configuration through set_unbounce_domains.
What is the impact if exploitation succeeds?
An attacker can redirect the plugin's front-end proxy to a host they control, causing arbitrary content to be served from the affected site's own origin.
Which plugin versions are affected?
Unbounce Landing Pages versions 1.1.1 through 1.1.4 are affected. Version 1.1.5 is identified as the first version not affected by the missing authorization check.