WordPress Plugin Vulnerabilities

WPLP Cookie Consent < 4.4.2 - Unauthenticated IAB TCF Consent Option Update

Description

The plugin does not have any authorisation or CSRF checks when storing visitor consent state, and the code that does so runs on every front-end page load, allowing unauthenticated attackers to overwrite a site-wide option with arbitrary data.

Proof of Concept

Affects Plugins

Fixed in 4.4.2

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
Alex Spataru
Submitter
Alex Spataru
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-09-07 (about 2 days ago)
Added
2026-09-07 (about 1 day ago)
Last Updated
2026-09-07 (about 1 day ago)

Other