AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-18046

MEDIUM · CVSS 4.3 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The Cookie Consent plugin for WordPress versions prior to 0.0.10 has a vulnerability that allows any authenticated user, including subscribers, to overwrite the geolocation service license key due to improper enforcement of administrator-only access on the REST route. This could lead to unauthorized changes in the consent banner targeting, potentially disrupting compliance with privacy regulations. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-18046
Severity
MEDIUM
CVSS
4.3
EPSS
0.18%
WordPress

Original NVD Description

The Cookie Consent WordPress plugin before 0.0.10 does not correctly enforce its intended administrator-only capability check on the REST route that stores its geolocation service license key, so the route falls back to an authentication-only gate, allowing any authenticated user such as a subscriber to overwrite the stored key and disrupt the Cookie Consent WordPress plugin before 0.0.10's geolocation-based consent banner targeting.