WP Legal Pages WordPress Plugin Missing Authorization Vulnerability Allows Arbitrary Plugin Installation

Vulnerability

A vulnerability exists in the WP Legal Pages WordPress plugin, specifically in the Privacy Policy Generator and Terms & Conditions Generator components, in all versions through 3.4.3. The issue arises from a missing capability check in the wplp_gdpr_install_plugin_ajax_handler() function, which allows authenticated attackers with Contributor-level access or higher to install arbitrary plugins from the repository.

Impact

Exploitation of this vulnerability could lead to unauthorized installation of plugins, potentially allowing for further exploitation or malicious activity on the affected WordPress site.

Remediation

Users are advised to update the WP Legal Pages WordPress plugin to version 3.4.4 or a newer patched version.

Added: Sep 18, 2025, 10:17 AM
Updated: Sep 18, 2025, 1:58 PM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
2.5
exploitability
6.1
remediation
7.7
relevance
0.5
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.