Description
The WPLP Cookie Consent WordPress plugin before 4.4.2 does not have any authorisation or CSRF checks when storing visitor consent state, and the code that does so runs on every front-end page load, allowing unauthenticated attackers to overwrite a site-wide option with arbitrary data.
Published:
2026-09-09
Score:
n/a
EPSS:
n/a
KEV:
No
Impact:
n/a
Action:
n/a
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Wed, 09 Sep 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WPLP Cookie Consent WordPress plugin before 4.4.2 does not have any authorisation or CSRF checks when storing visitor consent state, and the code that does so runs on every front-end page load, allowing unauthenticated attackers to overwrite a site-wide option with arbitrary data. | |
| Title | WPLP Cookie Consent < 4.4.2 - Unauthenticated IAB TCF Consent Option Update | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-09T06:00:06.932Z
Reserved: 2026-08-28T07:40:28.496Z
Link: CVE-2026-82184
No data.
Status : Received
Published: 2026-09-09T06:17:17.257
Modified: 2026-09-09T06:17:17.257
Link: CVE-2026-82184
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.