Wplp Cookie Consent

WordPress plugin · wplp-cookie-consent · WordPress.org ↗
0
Critical
1
High
7
Known total
0
Unfixed
Running Wplp Cookie Consent on your site? WP Alerts checks your installed version against every entry below and emails you only when one affects you. Free, no tracking.
Scan a site Monitor my sites →
SeverityVulnerabilityAffectedFixed inCVEPublished
HIGH
CVSS 8.8
WPLP Cookie Consent < 4.4.4 - Unauthenticated Stored XSS via Consent Logs
CVE.org
>=0, <4.4.4 v4.4.4 CVE-2026-85130 Sep 17, 2026
MEDIUM
CVSS 6.5
WPLP Cookie Consent < 4.4.4 - Arbitrary Post Deletion via CSRF
CVE.org
>=0, <4.4.4 v4.4.4 CVE-2026-85131 Sep 16, 2026
MEDIUM
CVSS 5.4
WPLP Cookie Consent < 4.4.2 - Subscriber+ Missing Authorization via Multiple Settings AJAX Actions
CVE.org
>=0, <4.4.2 v4.4.2 CVE-2026-85133 Sep 9, 2026
MEDIUM
CVSS 4.3
WPLP Cookie Consent 4.0.2 - 4.4.1 - Subscriber+ Cookie Scan Schedule Disclosure via gcc_get_schedule_scan
CVE.org
>=4.0.2, <4.4.2 v4.4.2 CVE-2026-85132 Sep 9, 2026
MEDIUM
CVSS 4.3
WPLP Cookie Consent < 4.4.2 - Subscriber+ Banner Settings Overwrite and A/B Test Data Reset
CVE.org
>=3.6.5, <4.4.2 v4.4.2 CVE-2026-82185 Sep 9, 2026
MEDIUM
CVSS 5.3
WPLP Cookie Consent < 4.4.2 - Unauthenticated IAB TCF Consent Option Update
CVE.org
>=3.5.0, <4.4.2 v4.4.2 CVE-2026-82184 Sep 9, 2026
MEDIUM
CVSS 4.1
WPLP Cookie Consent < 4.4.2 - Admin+ SQLi via 'offset' Parameter
CVE.org
>=3.0.0, <4.4.2 v4.4.2 CVE-2026-82186 Sep 4, 2026

Data aggregated from WPVulnerability, NVD/NIST, ENISA EUVD, CVE.org and WordPress.org. Provided as-is; verify with the plugin author before acting. Disclaimer.