The WPLP Cookie Consent WordPress plugin before 4.4.2 does not have any authorisation or CSRF checks when storing visitor consent state, and the code that does so runs on every front-end page load, allowing unauthenticated attackers to overwrite a site-wide option with arbitrary data.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 09 Sep 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WPLP Cookie Consent WordPress plugin before 4.4.2 does not have any authorisation or CSRF checks when storing visitor consent state, and the code that does so runs on every front-end page load, allowing unauthenticated attackers to overwrite a site-wide option with arbitrary data. | |
| Title | WPLP Cookie Consent < 4.4.2 - Unauthenticated IAB TCF Consent Option Update | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-09T06:00:06.932Z
Reserved: 2026-08-28T07:40:28.496Z
Link: CVE-2026-82184
No data.
Status : Received
Published: 2026-09-09T06:17:17.257
Modified: 2026-09-09T06:17:17.257
Link: CVE-2026-82184
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.