CVE-2026-82970: Malicious File Upload
Published Aug 31, 2026
·Updated
Unrestricted Upload of File with Dangerous Type vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent allows Using Malicious Files.
This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through 4.4.1.
Affected Software
1 affected component
WP Cookie Notice for GDPR, CCPA & ePrivacy Consent<=4.4.1
Event History
Aug 31, 2026
CVE Published
via NVD·03:18 PM
Data Sourced
via NVD·03:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which installations should be treated as affected?
WP Cookie Notice for GDPR, CCPA & ePrivacy Consent versions through 4.4.1 are affected. The earliest affected version is not specified.
2
Does exploitation require an account or user interaction?
No. The CVSS vector indicates network-based exploitation with low attack complexity, no privileges required, and no user interaction required.
3
What could successful exploitation affect?
The CVSS assessment rates confidentiality, integrity, and availability impacts as high, with scope changed. This indicates compromise may affect resources beyond the vulnerable component's original security authority.