Description
The WPLP Cookie Consent WordPress plugin before 4.4.4 does not escape a value submitted through a public endpoint for the JavaScript context it is later output in on an administrative screen, allowing unauthenticated users to run arbitrary JavaScript in the session of an administrator who interacts with the logged entry. Only multisite installations are affected.
Published: 2026-09-17
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated Stored XSS
Action: Immediate Patch
AI Analysis

Impact

The WPLP Cookie Consent WordPress plugin before version 4.4.4 contains a flaw that fails to escape a value supplied through a public endpoint. That value is later rendered within a JavaScript context on an administrative page, enabling an unauthenticated attacker to store and execute arbitrary JavaScript when an administrator views the related log entry. Because the privilege escalation occurs only in the browser session of the administrator, the vulnerability can be used to hijack the admin account, steal credentials, modify site content, or deface the site.

Affected Systems

The affected component is the WordPress plugin WPLP Cookie Consent, in any multisite WordPress installation running a version earlier than 4.4.4. Only multisite deployments expose the public logging endpoint that the flaw relies on, so single‑site installations are not affected by this issue.

Risk and Exploitability

The CVSS base score of 8.8 indicates high severity, and the low EPSS score (<1%) suggests that exploitation is unlikely at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires only an unauthenticated user to submit a crafted request to the public endpoint; no local or authenticated access is needed. An attacker can then force an administrator to view the malicious log entry, at which time the injected script runs with full administrative privileges in the administrator’s browser.

Generated by OpenCVE AI on September 18, 2026 at 01:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the WPLP Cookie Consent plugin to version 4.4.4 or newer.
  • Disable or remove the public consent‑log endpoint if it is not required, or restrict it to authenticated users only.
  • Review any custom code that interacts with the consent logs to ensure no unsanitized output remains.

Generated by OpenCVE AI on September 18, 2026 at 01:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The WPLP Cookie Consent WordPress plugin before 4.4.4 does not escape a value submitted through a public endpoint for the JavaScript context it is later output in on an administrative screen, allowing unauthenticated users to run arbitrary JavaScript in the session of an administrator who interacts with the logged entry. Only multisite installations are affected.
Title WPLP Cookie Consent < 4.4.4 - Unauthenticated Stored XSS via Consent Logs
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-17T12:30:33.334Z

Reserved: 2026-09-03T08:39:06.808Z

Link: CVE-2026-85130

cve-icon Vulnrichment

Updated: 2026-09-17T12:13:27.423Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T06:16:50.990

Modified: 2026-09-18T19:08:32.830

Link: CVE-2026-85130

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T02:00:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')