Unrestricted File Upload Vulnerability in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent by WP Legal Pages
CVE-2026-82970

10CRITICAL

What is CVE-2026-82970?

The WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin for WordPress contains a vulnerability that allows attackers to upload files with dangerous types. This flaw can be exploited to upload malicious files, potentially compromising the security of a website. Users of versions from n/a to 4.4.1 should take immediate action to mitigate risks associated with this vulnerability.

Affected Version(s)

WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.4.1

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jiemook | Patchstack Bug Bounty Program
.