VYPR
Medium severity5.3NVD Advisory· Published Nov 21, 2025· Updated Apr 27, 2026

CVE-2025-66077

CVE-2025-66077

Description

Missing Authorization vulnerability in wpWax Legal Pages legal-pages allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Legal Pages: from n/a through <= 1.4.6.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Missing authorization in WordPress Legal Pages plugin (≤1.4.6) allows unauthenticated attackers to exploit access control flaws.

The Legal Pages plugin for WordPress (versions up to and including 1.4.6) suffers from a missing authorization vulnerability. The flaw resides in the plugin's access control logic, where security checks for proper user capabilities or nonce tokens are absent, allowing exploitation of incorrectly configured access control security levels [1].

An attacker can exploit this vulnerability without requiring any authentication or special privileges. The attack vector is network-based, with low complexity, and no user interaction is needed. This makes it particularly dangerous for mass-exploit campaigns targeting thousands of WordPress sites simultaneously [1].

The impact is considered low in severity, but successful exploitation could allow an unprivileged user to perform actions intended for higher-privileged roles, such as modifying legal page settings or retrieving sensitive information. Given the prevalence of WordPress, this vulnerability poses a significant risk to site integrity [1].

Users are strongly advised to update the plugin to version 1.4.7 or later, which fixes the issue. For those unable to update, consulting hosting providers or web developers is recommended. Patchstack users can enable auto-updates for vulnerable plugins [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.