CVE-2026-75865: WPLP Cookie Consent <= 4.4.1 - Unauthenticated Arbitrary File Upload via 'upload-logo' REST Endpoint
The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the saasuploadlogo() function combined with an authorization bypass on the WPLP connector REST endpoints in all versions up to, and including, 4.4.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress plugin: WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Modeto a version that resolves this vulnerability.Fixed in 4.4.1
Event History
Frequently Asked Questions
Which installations are affected?
All versions of the WPLP Cookie Consent plugin up to and including 4.4.1 are affected. WordPress sites running a version in that range should be treated as exposed.
Does exploitation require a WordPress account or user interaction?
No. The affected REST endpoints have an authorization bypass, allowing unauthenticated attackers to upload arbitrary files without credentials or user interaction.
What is the practical impact of successful exploitation?
An attacker can upload arbitrary files to the affected server. This may enable remote code execution, with potential compromise of confidentiality, integrity, and availability.