Authorization Flaw in WPLP Cookie Consent Plugin for WordPress
CVE-2026-82184
Currently unrated
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 9 September 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-82184?
The WPLP Cookie Consent plugin for WordPress, prior to version 4.4.2, is susceptible to an authorization flaw, lacking necessary CSRF checks when handling visitor consent states. This vulnerability allows unauthenticated attackers to manipulate site-wide options, posing a significant risk by overwriting critical data on every front-end page access.
Affected Version(s)
WPLP Cookie Consent 3.5.0 < 4.4.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.