CVE-2026-85131: WPLP Cookie Consent < 4.4.4 - Arbitrary Post Deletion via CSRF

Published Sep 16, 2026
·
Updated

The WPLP Cookie Consent WordPress plugin before 4.4.4 does not perform CSRF or capability checks when processing bulk actions on its administration screens, and does not restrict the targeted items to its own records, allowing attackers to make a logged in admin permanently delete arbitrary posts and pages via a crafted request.

Affected Software

0 affected components

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade WPLP Cookie Consent to a version that resolves this vulnerability.

    Fixed in 4.4.4
  2. Compensating control

    Restrict access to the WordPress administration area (e.g., via network controls/ACL/firewall) so only trusted users can reach wp-admin.

Event History

Sep 16, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

WordPress sites using a WPLP Cookie Consent version earlier than 4.4.4 are exposed when an administrator is logged in and can be induced to send a crafted request.

2

What does an attacker need to exploit it?

The attacker needs to cause a logged-in WordPress administrator to submit a crafted request to the plugin's administration screens. No indication is provided that the attacker needs their own authenticated account.

3

What is the impact of a successful attack?

A successful attack can permanently delete arbitrary WordPress posts and pages. The affected items are not limited to records belonging to the WPLP Cookie Consent plugin.

4

How can I determine whether my site is affected?

Check whether WPLP Cookie Consent is installed and whether its version is earlier than 4.4.4. Sites without the plugin, or running version 4.4.4 or later, are not described as affected.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203