Unrestricted File Upload Vulnerability in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent by WP Legal Pages
CVE-2026-82970
10CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 31 August 2026
What is CVE-2026-82970?
The WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin for WordPress contains a vulnerability that allows attackers to upload files with dangerous types. This flaw can be exploited to upload malicious files, potentially compromising the security of a website. Users of versions from n/a to 4.4.1 should take immediate action to mitigate risks associated with this vulnerability.
Affected Version(s)
WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.4.1