Arbitrary File Upload Vulnerability in WPLP Cookie Consent Plugin for WordPress
CVE-2026-75865
9.8CRITICAL
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 1 September 2026
What is CVE-2026-75865?
The WPLP Cookie Consent plugin for WordPress has a vulnerability that allows for arbitrary file uploads. This is primarily due to insufficient file type validation in the saas_upload_logo() function, paired with an authorization bypass on the WPLP connector REST endpoints. This weakness affects all versions up to and including 4.4.1, enabling unauthenticated attackers to upload arbitrary files, potentially leading to remote code execution on the server hosting the affected site.
Affected Version(s)
WPLP Cookie Consent β Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode 0 <= 4.4.1