CVE-2026-82184 PUBLISHED

WPLP Cookie Consent < 4.4.2 - Unauthenticated IAB TCF Consent Option Update

Assigner: WPScan
Reserved: 28.08.2026 Published: 09.09.2026 Updated: 09.09.2026

The WPLP Cookie Consent WordPress plugin before 4.4.2 does not have any authorisation or CSRF checks when storing visitor consent state, and the code that does so runs on every front-end page load, allowing unauthenticated attackers to overwrite a site-wide option with arbitrary data.

Product Status

Vendor Unknown
Product WPLP Cookie Consent
Versions Default: unaffected
  • affected from 3.5.0 to 4.4.2 (excl.)

Credits

  • Alex Spataru finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE
  • CWE-352 Cross-Site Request Forgery (CSRF) CWE