All 3 CVE vulnerabilities found in WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode, with AI-generated Chinese analysis, references, and POCs.
Vendor: wplegalpages
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-75865 | WPLP Cookie Consent <= 4.4.1 - Unauthenticated Arbitrary File Upload via 'upload-logo' REST Endpoint CWE-434 | 9.8 | Critical | 2026-09-01 |
| CVE-2026-13360 | Cookie Banner for GDPR / CCPA <= 4.3.5 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'regionArray' Parameter CWE-79 | 7.2 | High | 2026-08-15 |
| CVE-2026-15136 | Cookie Banner for GDPR / CCPA – WPLP Cookie Consent <= 4.3.7 - Cross-Site Request Forgery via Bulk Action to Delete/Resolve Entries CWE-352 | 4.3 | Medium | 2026-07-28 |
All 3 known CVE vulnerabilities affecting WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode with full Chinese analysis, references, and POCs where available.