Stored Cross-Site Scripting in WPLP Cookie Consent Plugin for WordPress
CVE-2026-14989
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 9 September 2026
What is CVE-2026-14989?
The WPLP Cookie Consent plugin for WordPress is susceptible to stored cross-site scripting attacks due to inadequate input sanitization of the 'wpl_user_preference' parameter. All versions up to and including 4.4.1 are affected. This vulnerability allows unauthenticated attackers to inject arbitrary scripts that execute whenever a user accesses compromised pages. The problem is exacerbated by the fact that the consent-logging AJAX endpoint is open to unauthenticated users, with a nonce that is publicly available on the frontend. These security flaws grant attackers the ability to exploit the plugin without any authentication, potentially leading to significant impacts on website security.
Affected Version(s)
WPLP Cookie Consent β Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode 0 <= 4.4.1