Stored Cross-Site Scripting Vulnerability in WPLP Cookie Consent Plugin for WordPress
CVE-2026-13360

7.2HIGH

What is CVE-2026-13360?

The WPLP Cookie Consent plugin for WordPress contains a vulnerability that allows unauthenticated attackers to execute arbitrary web scripts on affected sites. This arises from insufficient input sanitization and output escaping of the 'regionArray' parameter, evident across all versions up to and including 4.3.5. Exploitation of this vulnerability is contingent upon the administrator enabling the 'Support Google Consent Mode (GCM)' setting, which is turned off by default. Additionally, the AJAX handler lacks nonce or capability checks, permitting any authenticated user—including those with only Subscriber access—to modify the plugin's settings.

Affected Version(s)

WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode 0 <= 4.3.5

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Naoya Takahashi (nakko)
.