Arbitrary File Upload Vulnerability in WPLP Cookie Consent Plugin for WordPress
CVE-2026-75865

9.8CRITICAL

What is CVE-2026-75865?

The WPLP Cookie Consent plugin for WordPress has a vulnerability that allows for arbitrary file uploads. This is primarily due to insufficient file type validation in the saas_upload_logo() function, paired with an authorization bypass on the WPLP connector REST endpoints. This weakness affects all versions up to and including 4.4.1, enabling unauthenticated attackers to upload arbitrary files, potentially leading to remote code execution on the server hosting the affected site.

Affected Version(s)

WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode 0 <= 4.4.1

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Supakiad S. (m3ez)
.