Impact
The WPLP Cookie Consent WordPress plugin before version 4.4 verify the user’s capability when processing bulk actions on its administrative screens. A logged‑in administrator can therefore send a crafted HTTP request that triggers the plugin to permanently delete any post or page on the site, regardless of whether those items belong to the plugin. This flaw allows an attacker who has the credentials of an administrator to remove arbitrary content, resulting in data loss and potential site disruption.
Affected Systems
WordPress sites that have in a version earlier than 4.4.4 are affected. This includes any installation using version 4.4.3 or older. Because the vulnerability is tied to the plugin’s code and not a generic system component, it does not rely on any site with the unpatched plugin is vulnerable.
Risk and Exploitability
The EPSS score is less than 1 % and the vulnerability is not listed in CISA’s KEV catalog exploitation at present. However, the flaw requires only an authenticated administrator session and a single HTTP request, making it trivial for an attacker who has logged The severity is high within the scope of data loss, as the attacker can permanently remove posts and pages, which may hamper site erase valuable data. The absence of a CVSS score in the advisory does not diminish the practical impact of the vulnerability on affected sites.
OpenCVE Enrichment