WP Legal Pages
cpe:2.3:a:wplegalpages:wp_legal_pages:*:*:*:*:wordpress:*:*
- <= 3.4.3
A vulnerability exists in the WP Legal Pages WordPress plugin, specifically in the Privacy Policy Generator and Terms & Conditions Generator components, in all versions through 3.4.3. The issue arises from a missing capability check in the wplp_gdpr_install_plugin_ajax_handler() function, which allows authenticated attackers with Contributor-level access or higher to install arbitrary plugins from the repository.
Exploitation of this vulnerability could lead to unauthorized installation of plugins, potentially allowing for further exploitation or malicious activity on the affected WordPress site.
Users are advised to update the WP Legal Pages WordPress plugin to version 3.4.4 or a newer patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.