PT-2026-84075 · WordPress · Wp Cookie Consent
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode versions prior to 4.4.2
Description
An arbitrary file upload issue exists due to missing file type validation in the
saas upload logo() function combined with an authorization bypass on the WPLP connector REST endpoints. This allows unauthenticated remote attackers to upload arbitrary files to the server, which may lead to remote code execution (RCE), a state where an attacker can execute malicious commands on the affected system.Recommendations
Update WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode to a version newer than 4.4.1.
As a temporary mitigation, disable or remove the plugin until the update is applied.
Fix
RCE
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp Cookie Consent