SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-82970

CRITICAL · CVSS 10 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-08-31 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin versions up to 4.4.1 are vulnerable to an unrestricted file upload flaw, enabling attackers to upload and execute malicious files on the server. This critical vulnerability poses a severe risk, as it could lead to unauthorized access, data breaches, or complete server compromise. Organizations using this plugin should prioritize immediate remediation to mitigate potential exploitation.

CVE
CVE-2026-82970
Severity
CRITICAL
CVSS
10
EPSS
0.29%

Original NVD Description

Unrestricted Upload of File with Dangerous Type vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent allows Using Malicious Files. This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through 4.4.1.