Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

wplegalpages — Vulnerabilities & Security Advisories 16

Browse all 16 CVE security advisories affecting wplegalpages. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Wplegalpages is a WordPress plugin designed to help website owners create legal pages and documents. Historically, it has been vulnerable to multiple security issues including cross-site scripting (XSS), remote code execution (RCE), and privilege escalation vulnerabilities. These flaws often stem from insufficient input validation and improper access controls. The plugin has accumulated 9 CVE records, with some vulnerabilities allowing attackers to execute arbitrary code or gain elevated privileges. While no major public incidents have been widely documented, the consistent pattern of security issues across multiple versions indicates ongoing challenges in secure development practices.

CVE ID Title CVSS Severity Published
CVE-2026-14989 Cookie Banner for GDPR / CCPA <= 4.4.1 - Unauthenticated Stored Cross-Site Scripting via 'wpl_user_preference' Parameter — WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode CWE-79 7.2 High 2026-09-09
CVE-2026-75865 WPLP Cookie Consent <= 4.4.1 - Unauthenticated Arbitrary File Upload via 'upload-logo' REST Endpoint — WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode CWE-434 9.8 Critical 2026-09-01
CVE-2026-13360 Cookie Banner for GDPR / CCPA <= 4.3.5 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'regionArray' Parameter — WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode CWE-79 7.2 High 2026-08-15
CVE-2026-15136 Cookie Banner for GDPR / CCPA – WPLP Cookie Consent <= 4.3.7 - Cross-Site Request Forgery via Bulk Action to Delete/Resolve Entries — WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode CWE-352 4.3 Medium 2026-07-28
CVE-2026-12955 Cookie Banner for GDPR / CCPA <= 4.3.6 - Missing Authorization to Authenticated (Subscriber+) Scan Schedule Modification via gcc_save_schedule_scan AJAX Action — Cookie Banner for GDPR / CCPA – WPLP Cookie Consent CWE-862 4.3 Medium 2026-07-10
CVE-2026-14475 Cookie Banner for GDPR / CCPA <= 4.3.6 - Authenticated (Administrator+) SQL Injection via 'scan_id' Parameter — Cookie Banner for GDPR / CCPA – WPLP Cookie Consent CWE-89 4.9 Medium 2026-07-10
CVE-2026-12920 Cookie Banner for GDPR / CCPA <= 4.3.5 - Authenticated (Administrator+) SQL Injection via 's' Parameter — Cookie Banner for GDPR / CCPA – WPLP Cookie Consent CWE-89 4.9 Medium 2026-07-03
CVE-2025-11754 Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Consent <= 4.1.2 - Missing Authorization to Sensitive Information Exposure — Cookie Banner for GDPR / CCPA – WPLP Cookie Consent CWE-862 7.5 High 2026-02-19
CVE-2025-14061 Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Consent <= 4.0.7 - Missing Authorization to Unauthenticated Arbitrary Post Deletion — Cookie Banner for GDPR / CCPA – WPLP Cookie Consent CWE-862 5.3 Medium 2025-12-17
CVE-2025-11816 Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages <= 3.5.1 - Missing Authorization to Unauthenticated API Disconnect — Privacy Policy Generator – WPLP Legal Pages CWE-862 5.3 Medium 2025-11-01
CVE-2025-8565 Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages <= 3.4.3 - Missing Authorization to Authenticated (Contributor+) Arbitrary Plugin Installation — Privacy Policy Generator – WPLP Legal Pages CWE-862 8.1 High 2025-09-18
CVE-2024-12636 Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages <= 3.2.7 - Cross-Site Request Forgery — Privacy Policy Generator – WPLP Legal Pages CWE-352 4.3 Medium 2024-12-25
CVE-2024-11724 Cookie Consent for WP – Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) <= 3.6.5 - Missing Authorization to Authenticated (Subscriber+) Whitelist Script — Cookie Banner for GDPR / CCPA – WPLP Cookie Consent CWE-862 4.3 Medium 2024-12-12
CVE-2024-4869 WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) <= 3.2.0 - Unauthenticated Stored Cross-Site Scripting via Client-IP header — Cookie Banner for GDPR / CCPA – WPLP Cookie Consent CWE-79 7.2 High 2024-06-25
CVE-2024-3599 WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) <= 3.0.2 - Missing Authorization to Unauthenticated Arbitrary Post Deletion — Cookie Banner for GDPR / CCPA – WPLP Cookie Consent CWE-862 5.3 Medium 2024-05-02
CVE-2023-4968 WPLegalPages <= 2.9.2 - Authenticated (Author+) Stored Cross-Site Scripting via Shortcode — Privacy Policy Generator – WPLP Legal Pages CWE-79 5.5 Medium 2023-10-20

This page lists every published CVE security advisory associated with wplegalpages. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.