The WPLP Cookie Consent WordPress plugin before 4.4.2 does not perform nonce or capability checks on several of its settings AJAX actions, allowing any authenticated user, such as a subscriber, to read and destroy scan data belonging to the administrator and to overwrite the WPLP Cookie Consent WordPress plugin before 4.4.2's stored configuration.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-09 06:17
Updated : 2026-09-09 16:17
NVD link : CVE-2026-85133
Mitre link : CVE-2026-85133
CVE.ORG link : CVE-2026-85133
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
