Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Eran Kapeluto

#44386of 56,337
6.5Total CVSS
Vulnerabilities · 1
PT-2026-67029
6.5
2026-08-02
WordPress · Webtoffee-Cookie-Consent · CVE-2026-13389
**Name of the Vulnerable Software and Affected Versions** webtoffee-cookie-consent WordPress plugin versions prior to 3.5.3 **Description** Several REST API routes lack proper authorization checks, which allows unauthenticated attackers to export and delete stored visitor consent records, create posts, and modify the licensing state of the plugin. **Recommendations** Update webtoffee-cookie-consent WordPress plugin to version 3.5.3 or later.