WordPress · Webtoffee-Cookie-Consent · CVE-2026-13389
**Name of the Vulnerable Software and Affected Versions**
webtoffee-cookie-consent WordPress plugin versions prior to 3.5.3
**Description**
Several REST API routes lack proper authorization checks, which allows unauthenticated attackers to export and delete stored visitor consent records, create posts, and modify the licensing state of the plugin.
**Recommendations**
Update webtoffee-cookie-consent WordPress plugin to version 3.5.3 or later.