Unauthorized Access Vulnerability in WPLP Cookie Consent Plugin for WordPress
CVE-2026-85133
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 9 September 2026
Badges
What is CVE-2026-85133?
The WPLP Cookie Consent plugin for WordPress prior to version 4.4.2 suffers from an access control weakness due to the absence of nonce and capability checks on various AJAX actions. This flaw permits any authenticated user, including those with minimal privileges such as subscribers, to gain unauthorized access to sensitive configuration settings. As a result, they can read and potentially delete scan data that belongs to administrators, as well as modify the plugin's stored configurations, undermining the security and integrity of the application.
Affected Version(s)
WPLP Cookie Consent 0 < 4.4.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.