CVE-2026-22490

MEDIUM

WordPress LPagery <= 2.4.9 - Missing Authorization Access Control Bypass

Title source: manual
STIX 2.1

Description

Missing Authorization vulnerability in niklaslindemann Bulk Landing Page Creator for WordPress LPagery lpagery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bulk Landing Page Creator for WordPress LPagery: from n/a through <= 2.4.9.

Scores

CVSS v3 5.4
EPSS 0.0017
EPSS Percentile 6.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (1)
niklaslindemann/Bulk Landing Page Creator for WordPress LPagery < 2.4.9
Published Jan 08, 2026
Tracked Since Feb 18, 2026