Stored Cross-Site Scripting Vulnerability in WPLP Cookie Consent Plugin for WordPress
CVE-2026-13360
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 15 August 2026
What is CVE-2026-13360?
The WPLP Cookie Consent plugin for WordPress contains a vulnerability that allows unauthenticated attackers to execute arbitrary web scripts on affected sites. This arises from insufficient input sanitization and output escaping of the 'regionArray' parameter, evident across all versions up to and including 4.3.5. Exploitation of this vulnerability is contingent upon the administrator enabling the 'Support Google Consent Mode (GCM)' setting, which is turned off by default. Additionally, the AJAX handler lacks nonce or capability checks, permitting any authenticated user—including those with only Subscriber access—to modify the plugin's settings.
Affected Version(s)
WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode 0 <= 4.3.5