CVE-2026-82184
Deferred Deferred - Pending Action

WPLP Cookie Consent WordPress Plugin CSRF Vulnerability

Vulnerability report for CVE-2026-82184, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-09

Assigner: WPScan

Description

The WPLP Cookie Consent WordPress plugin before 4.4.2 does not have any authorisation or CSRF checks when storing visitor consent state, and the code that does so runs on every front-end page load, allowing unauthenticated attackers to overwrite a site-wide option with arbitrary data.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-09
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wplp cookie_consent to 4.4.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The WPLP Cookie Consent WordPress plugin before version 4.4.2 has a flaw where it lacks authorization and CSRF checks when storing visitor consent state. This allows unauthenticated attackers to overwrite site-wide options with arbitrary data by exploiting code that runs on every front-end page load.

Detection Guidance

Check if the WPLP Cookie Consent plugin version is below 4.4.2. Inspect network traffic for unauthenticated POST requests to WordPress admin-ajax.php handling consent state updates. Look for unusual site-wide option changes in the WordPress database.

Impact Analysis

An attacker could manipulate site-wide settings, potentially altering cookie consent behavior or injecting malicious content. This could disrupt site functionality or mislead users about privacy practices.

Compliance Impact

This vulnerability could lead to non-compliance with privacy regulations like GDPR or HIPAA by allowing unauthorized changes to consent mechanisms, potentially violating data protection requirements.

Mitigation Strategies

Update the WPLP Cookie Consent plugin to version 4.4.2 or later immediately. If updating is not possible, consider disabling the plugin temporarily until an update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82184. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart