CVE-2026-85133: WPLP Cookie Consent < 4.4.2 - Subscriber+ Missing Authorization via Multiple Settings AJAX Actions
The WPLP Cookie Consent WordPress plugin before 4.4.2 does not perform nonce or capability checks on several of its settings AJAX actions, allowing any authenticated user, such as a subscriber, to read and destroy scan data belonging to the administrator and to overwrite the WPLP Cookie Consent WordPress plugin before 4.4.2's stored configuration.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WPLP Cookie Consent WordPress pluginto a version that resolves this vulnerability.Fixed in 4.4.2
Event History
Frequently Asked Questions
Who can exploit the affected AJAX actions?
Any authenticated WordPress user can exploit them, including users with only the Subscriber role. No administrator-level permissions are required.
What can an attacker do through the missing authorization checks?
An authenticated attacker can read and destroy scan data belonging to an administrator and overwrite the plugin's stored configuration.
Which plugin versions are affected?
Versions of WPLP Cookie Consent before 4.4.2 are affected.