Unknown WPLP Cookie Consent

7 known vulnerabilities in Unknown WPLP Cookie Consent, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-85130 CVSS 8.8 high The WPLP Cookie Consent WordPress plugin before 4.4.4 does not escape a value submitted through a public endpoint for the JavaScript…
  • CVE-2026-85131 CVSS 6.5 medium The WPLP Cookie Consent WordPress plugin before 4.4.4 does not perform CSRF or capability checks when processing bulk actions on its…
  • CVE-2026-85133 CVSS 5.4 medium The WPLP Cookie Consent WordPress plugin before 4.4.2 does not perform nonce or capability checks on several of its settings AJAX actions…
  • CVE-2026-85132 CVSS 4.3 medium The WPLP Cookie Consent WordPress plugin before 4.4.2 does not perform nonce or capability checks on one of its cookie scanner AJAX…
  • CVE-2026-82185 CVSS 4.3 medium The WPLP Cookie Consent WordPress plugin before 4.4.2 does not have capability or nonce checks on some of its A/B testing actions…
  • CVE-2026-82184 CVSS 5.3 medium The WPLP Cookie Consent WordPress plugin before 4.4.2 does not have any authorisation or CSRF checks when storing visitor consent state…
  • CVE-2026-82186 CVSS 4.1 medium The WPLP Cookie Consent WordPress plugin before 4.4.2 does not properly validate a pagination parameter before using it in a SQL query…