CVE-2026-85132 PUBLISHED

WPLP Cookie Consent 4.0.2 - 4.4.1 - Subscriber+ Cookie Scan Schedule Disclosure via gcc_get_schedule_scan

Assigner: WPScan
Reserved: 03.09.2026 Published: 09.09.2026 Updated: 09.09.2026

The WPLP Cookie Consent WordPress plugin before 4.4.2 does not perform nonce or capability checks on one of its cookie scanner AJAX actions, allowing any authenticated user, such as a subscriber, to read back the automated scan schedule the administrator configured.

Product Status

Vendor Unknown
Product WPLP Cookie Consent
Versions Default: unaffected
  • affected from 4.0.2 to 4.4.2 (excl.)

Credits

  • Karthik Ramakrishnan finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE