CVE-2026-13389 PUBLISHED

WebToffee Cookie Consent < 3.5.3 - Consent Log Disclosure/Deletion, Page Creation & License Deactivation via Unprotected REST Routes

Assigner: WPScan
Reserved: 26.06.2026 Published: 02.08.2026 Updated: 02.08.2026

The webtoffee-cookie-consent WordPress plugin before 3.5.3 does not perform authorization checks on several of its REST API routes, allowing unauthenticated attackers to export and delete stored visitor consent records, create posts, and modify the webtoffee-cookie-consent WordPress plugin before 3.5.3's licensing state.

Product Status

Vendor Unknown
Product webtoffee-cookie-consent
Versions Default: unaffected
  • affected from 0 to 3.5.3 (excl.)

Credits

  • Eran Kapeluto finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE