Stored Cross-Site Scripting in WPLP Cookie Consent Plugin for WordPress
CVE-2026-14989

7.2HIGH

What is CVE-2026-14989?

The WPLP Cookie Consent plugin for WordPress is susceptible to stored cross-site scripting attacks due to inadequate input sanitization of the 'wpl_user_preference' parameter. All versions up to and including 4.4.1 are affected. This vulnerability allows unauthenticated attackers to inject arbitrary scripts that execute whenever a user accesses compromised pages. The problem is exacerbated by the fact that the consent-logging AJAX endpoint is open to unauthenticated users, with a nonce that is publicly available on the frontend. These security flaws grant attackers the ability to exploit the plugin without any authentication, potentially leading to significant impacts on website security.

Affected Version(s)

WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode 0 <= 4.4.1

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Naoya Takahashi (nakko)
.