CVE-2026-85574: Unbounce Landing Pages 1.1.1 - 1.1.4 - Subscriber+ Reverse-Proxy Target Hijack via set_unbounce_domains

Published Sep 19, 2026
·
Updated

The Unbounce Landing Pages WordPress plugin before 1.1.5 does not perform any authorisation check when updating the configuration its front-end proxy relies on, allowing any authenticated user, such as a subscriber, to point that proxy at a host they control and have arbitrary content served from the site's own origin.

Affected Software

1 affected component
Unbounce Unbounce Landing Pages>=1.1.1<1.1.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Unbounce Landing Pages WordPress plugin to a version that resolves this vulnerability.

    Fixed in 1.1.5
  2. Compensating control

    Restrict which users can update Unbounce Landing Pages configuration (e.g., limit to administrators) to prevent authenticated users (such as subscribers) from hijacking the front-end reverse-proxy target via set_unbounce_domains in Unbounce Landing Pages 1.1.1 - 1.1.4.

Event History

Sep 19, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any authenticated WordPress user can exploit it, including users with only the Subscriber role. No elevated WordPress administrative capability is required.

2

What does an attacker need to do to exploit it?

The attacker needs a valid authenticated account on the affected WordPress site and control of a host they can configure as the proxy target. They can then change the front-end proxy configuration through set_unbounce_domains.

3

What is the impact if exploitation succeeds?

An attacker can redirect the plugin's front-end proxy to a host they control, causing arbitrary content to be served from the affected site's own origin.

4

Which plugin versions are affected?

Unbounce Landing Pages versions 1.1.1 through 1.1.4 are affected. Version 1.1.5 is identified as the first version not affected by the missing authorization check.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203