CVE-2026-85132

The WPLP Cookie Consent WordPress plugin before 4.4.2 does not perform nonce or capability checks on one of its cookie scanner AJAX actions, allowing any authenticated user, such as a subscriber, to read back the automated scan schedule the administrator configured.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-09 06:17

Updated : 2026-09-09 16:17


NVD link : CVE-2026-85132

Mitre link : CVE-2026-85132

CVE.ORG link : CVE-2026-85132


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization