Impact
The WPLP Cookie Consent WordPress plugin before version 4.4.4 contains a flaw that fails to escape a value supplied through a public endpoint. That value is later rendered within a JavaScript context on an administrative page, enabling an unauthenticated attacker to store and execute arbitrary JavaScript when an administrator views the related log entry. Because the privilege escalation occurs only in the browser session of the administrator, the vulnerability can be used to hijack the admin account, steal credentials, modify site content, or deface the site.
Affected Systems
The affected component is the WordPress plugin WPLP Cookie Consent, in any multisite WordPress installation running a version earlier than 4.4.4. Only multisite deployments expose the public logging endpoint that the flaw relies on, so single‑site installations are not affected by this issue.
Risk and Exploitability
The CVSS base score of 8.8 indicates high severity, and the low EPSS score (<1%) suggests that exploitation is unlikely at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires only an unauthenticated user to submit a crafted request to the public endpoint; no local or authenticated access is needed. An attacker can then force an administrator to view the malicious log entry, at which time the injected script runs with full administrative privileges in the administrator’s browser.
OpenCVE Enrichment