CVE-2026-85131: WPLP Cookie Consent < 4.4.4 - Arbitrary Post Deletion via CSRF
The WPLP Cookie Consent WordPress plugin before 4.4.4 does not perform CSRF or capability checks when processing bulk actions on its administration screens, and does not restrict the targeted items to its own records, allowing attackers to make a logged in admin permanently delete arbitrary posts and pages via a crafted request.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WPLP Cookie Consentto a version that resolves this vulnerability.Fixed in 4.4.4 - Compensating control
Restrict access to the WordPress administration area (e.g., via network controls/ACL/firewall) so only trusted users can reach wp-admin.
Event History
Frequently Asked Questions
Who is exposed to this issue?
WordPress sites using a WPLP Cookie Consent version earlier than 4.4.4 are exposed when an administrator is logged in and can be induced to send a crafted request.
What does an attacker need to exploit it?
The attacker needs to cause a logged-in WordPress administrator to submit a crafted request to the plugin's administration screens. No indication is provided that the attacker needs their own authenticated account.
What is the impact of a successful attack?
A successful attack can permanently delete arbitrary WordPress posts and pages. The affected items are not limited to records belonging to the WPLP Cookie Consent plugin.
How can I determine whether my site is affected?
Check whether WPLP Cookie Consent is installed and whether its version is earlier than 4.4.4. Sites without the plugin, or running version 4.4.4 or later, are not described as affected.