CVE-2026-82186 PUBLISHED

WPLP Cookie Consent < 4.4.2 - Admin+ SQLi via 'offset' Parameter

Assigner: WPScan
Reserved: 28.08.2026 Published: 04.09.2026 Updated: 04.09.2026

The WPLP Cookie Consent WordPress plugin before 4.4.2 does not properly validate a pagination parameter before using it in a SQL query, allowing users with administrator privileges to perform SQL injection attacks.

Product Status

Vendor Unknown
Product WPLP Cookie Consent
Versions Default: unaffected
  • affected from 3.0.0 to 4.4.2 (excl.)

Credits

  • cyberkareem finder
  • WPScan coordinator

References

Problem Types

  • CWE-89 SQL Injection CWE