CVE-2026-85133 PUBLISHED

WPLP Cookie Consent < 4.4.2 - Subscriber+ Missing Authorization via Multiple Settings AJAX Actions

Assigner: WPScan
Reserved: 03.09.2026 Published: 09.09.2026 Updated: 09.09.2026

The WPLP Cookie Consent WordPress plugin before 4.4.2 does not perform nonce or capability checks on several of its settings AJAX actions, allowing any authenticated user, such as a subscriber, to read and destroy scan data belonging to the administrator and to overwrite the WPLP Cookie Consent WordPress plugin before 4.4.2's stored configuration.

Product Status

Vendor Unknown
Product WPLP Cookie Consent
Versions Default: unaffected
  • affected from 0 to 4.4.2 (excl.)

Credits

  • Naoki Kawahigashi finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE