SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-85133

MEDIUM · CVSS 5.4 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The WPLP Cookie Consent plugin for WordPress prior to version 4.4.2 is vulnerable due to the lack of nonce and capability checks on its AJAX actions, enabling any authenticated user, including subscribers, to manipulate the plugin's settings. This vulnerability allows unauthorized access to sensitive scan data and the ability to overwrite the plugin's configuration, potentially compromising site integrity. WordPress administrators using this plugin should prioritize updating to version 4.4.2 or later to mitigate these risks.

CVE
CVE-2026-85133
Severity
MEDIUM
CVSS
5.4
EPSS
0.14%
WordPress

Original NVD Description

The WPLP Cookie Consent WordPress plugin before 4.4.2 does not perform nonce or capability checks on several of its settings AJAX actions, allowing any authenticated user, such as a subscriber, to read and destroy scan data belonging to the administrator and to overwrite the WPLP Cookie Consent WordPress plugin before 4.4.2's stored configuration.