SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-85132

MEDIUM · CVSS 4.3 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The WPLP Cookie Consent plugin for WordPress versions prior to 4.4.2 is vulnerable due to the lack of nonce and capability checks on its cookie scanner AJAX actions, enabling any authenticated user, including subscribers, to access the automated scan schedule set by the administrator. This exposure could lead to unauthorized insights into site configurations and potential exploitation by malicious users. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-85132
Severity
MEDIUM
CVSS
4.3
EPSS
0.16%
WordPress

Original NVD Description

The WPLP Cookie Consent WordPress plugin before 4.4.2 does not perform nonce or capability checks on one of its cookie scanner AJAX actions, allowing any authenticated user, such as a subscriber, to read back the automated scan schedule the administrator configured.