CVE-2026-18046: Cookie Consent < 0.0.10 - Subscriber+ MaxMind License Key Update
The Cookie Consent WordPress plugin before 0.0.10 does not correctly enforce its intended administrator-only capability check on the REST route that stores its geolocation service license key, so the route falls back to an authentication-only gate, allowing any authenticated user such as a subscriber to overwrite the stored key and disrupt the Cookie Consent WordPress plugin before 0.0.10's geolocation-based consent banner targeting.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cookie Consent WordPress pluginto a version that resolves this vulnerability.Fixed in 0.0.10 - Operational
After upgrading Cookie Consent WordPress plugin to 0.0.10, update/verify the stored geolocation service license key to ensure an authenticated user could not overwrite it in versions before 0.0.10.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18046?
CVE-2026-18046 has a risk score of 35, indicating a moderate severity vulnerability.
How do I fix CVE-2026-18046?
To mitigate CVE-2026-18046, update the Cookie Consent WordPress plugin to version 0.0.10 or higher.
What does CVE-2026-18046 affect?
CVE-2026-18046 affects versions of the Cookie Consent WordPress plugin prior to 0.0.10.
Who can exploit CVE-2026-18046?
CVE-2026-18046 can be exploited by any authenticated user, such as a subscriber, due to insufficient access controls.
What functionality is impacted by CVE-2026-18046?
CVE-2026-18046 impacts the REST route that stores the geolocation service license key for the Cookie Consent plugin.