The WPLP Cookie Consent WordPress plugin before 4.4.2 does not have any authorisation or CSRF checks when storing visitor consent state, and the code that does so runs on every front-end page load, allowing unauthenticated attackers to overwrite a site-wide option with arbitrary data.
Metrics
Affected Vendors & Products
References
History
Wed, 09 Sep 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 CWE-352 |
Wed, 09 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-862 | |
| Metrics |
cvssV3_1
|
Wed, 09 Sep 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 CWE-352 |
Wed, 09 Sep 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WPLP Cookie Consent WordPress plugin before 4.4.2 does not have any authorisation or CSRF checks when storing visitor consent state, and the code that does so runs on every front-end page load, allowing unauthenticated attackers to overwrite a site-wide option with arbitrary data. | |
| Title | WPLP Cookie Consent < 4.4.2 - Unauthenticated IAB TCF Consent Option Update | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published: 2026-09-09T06:00:06.932Z
Updated: 2026-09-09T15:38:24.007Z
Reserved: 2026-08-28T07:40:28.496Z
Link: CVE-2026-82184
Updated: 2026-09-09T15:32:49.430Z
Status : Deferred
Published: 2026-09-09T06:17:17.257
Modified: 2026-09-09T16:17:11.140
Link: CVE-2026-82184
No data.