SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-82185

MEDIUM · CVSS 4.3 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The WPLP Cookie Consent plugin for WordPress versions prior to 4.4.2 is vulnerable due to the absence of capability and nonce checks on certain A/B testing actions. This allows any authenticated user, including subscribers, to modify the cookie banner settings for all visitors and permanently erase stored A/B test results. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential unauthorized changes and data loss.

CVE
CVE-2026-82185
Severity
MEDIUM
CVSS
4.3
EPSS
0.15%
WordPress

Original NVD Description

The WPLP Cookie Consent WordPress plugin before 4.4.2 does not have capability or nonce checks on some of its A/B testing actions, allowing any authenticated user, such as a subscriber, to overwrite the cookie banner configuration shown to every visitor and to irreversibly reset the stored A/B test results.