Browse all 9 CVE security advisories affecting wplegalpages. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Wplegalpages is a WordPress plugin designed to help website owners create legal pages and documents. Historically, it has been vulnerable to multiple security issues including cross-site scripting (XSS), remote code execution (RCE), and privilege escalation vulnerabilities. These flaws often stem from insufficient input validation and improper access controls. The plugin has accumulated 9 CVE records, with some vulnerabilities allowing attackers to execute arbitrary code or gain elevated privileges. While no major public incidents have been widely documented, the consistent pattern of security issues across multiple versions indicates ongoing challenges in secure development practices.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-11816 | Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages <= 3.5.1 - Missing Authorization to Unauthenticated API Disconnect — Privacy Policy Generator – WPLP Legal PagesCWE-862 | 5.3 | Medium | 2025-11-01 |
| CVE-2025-8565 | Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages <= 3.4.3 - Missing Authorization to Authenticated (Contributor+) Arbitrary Plugin Installation — Privacy Policy Generator – WPLP Legal PagesCWE-862 | 8.1 | High | 2025-09-18 |
| CVE-2024-12636 | Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages <= 3.2.7 - Cross-Site Request Forgery — Privacy Policy Generator – WPLP Legal PagesCWE-352 | 4.3 | Medium | 2024-12-25 |
| CVE-2023-4968 | WPLegalPages <= 2.9.2 - Authenticated (Author+) Stored Cross-Site Scripting via Shortcode — Privacy Policy Generator – WPLP Legal PagesCWE-79 | 5.5 | Medium | 2023-10-20 |
This page lists every published CVE security advisory associated with wplegalpages. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.