Legal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator

This information is sourced from wpvulnerabilities.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Vulnerabilities

  • Input validation vulnerability in Legal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator 1.4.2

    Fixed

    The Legal Pages plugin for WordPress has a security issue called Cross-Site Request Forgery. This can happen in versions 1.4.2 and below. The problem is that the plugin does not properly check for a ...

    Read More
  • Input validation vulnerability in Legal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator 1.3.8

    Fixed

    The Legal Pages plugin for WordPress is not secure in versions up to 1.3.8. An unauthenticated attacker can potentially manipulate the plugin in order to delete posts and insert template data without...

    Read More
  • Access violation vulnerability in Legal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator 1.3.8

    Fixed

    The Legal Pages plugin for WordPress is not secure in versions up to, and including, 1.3.7. This means that people with subscriber-level access or higher can delete legal templates without permission...

    Read More
  • Access violation vulnerability in Legal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator 1.3.8

    Fixed

    The Legal Pages plugin for WordPress, used to generate privacy policies, terms and conditions, GDPR, CCPA, and cookie notices, is vulnerable to unauthorized changes in all versions up to 1.3.8. Attac...

    Read More
  • Input validation vulnerability in Appsero analytics tool 1.2.0 (41 plugins affected)

    Fixed

    The Appsero analytics tool

    Read More
  • Access violation vulnerability in Appsero analytics tool 1.2.1 (41 plugins affected)

    Fixed

    Several plugins are using the Appsero analytics tool, but it is vulnerable to authorization bypass due to a missing capability check on a function used for feedback submission in versions up to 1.2.1....

    Read More