Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

wplegalpages — Vulnerabilities & Security Advisories 16

Browse all 16 CVE security advisories affecting wplegalpages. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Wplegalpages is a WordPress plugin designed to help website owners create legal pages and documents. Historically, it has been vulnerable to multiple security issues including cross-site scripting (XSS), remote code execution (RCE), and privilege escalation vulnerabilities. These flaws often stem from insufficient input validation and improper access controls. The plugin has accumulated 9 CVE records, with some vulnerabilities allowing attackers to execute arbitrary code or gain elevated privileges. While no major public incidents have been widely documented, the consistent pattern of security issues across multiple versions indicates ongoing challenges in secure development practices.

Found 4 results / 16 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-14989 Cookie Banner for GDPR / CCPA <= 4.4.1 - Unauthenticated Stored Cross-Site Scripting via 'wpl_user_preference' Parameter — WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode CWE-79 7.2 High 2026-09-09
CVE-2026-75865 WPLP Cookie Consent <= 4.4.1 - Unauthenticated Arbitrary File Upload via 'upload-logo' REST Endpoint — WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode CWE-434 9.8 Critical 2026-09-01
CVE-2026-13360 Cookie Banner for GDPR / CCPA <= 4.3.5 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'regionArray' Parameter — WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode CWE-79 7.2 High 2026-08-15
CVE-2026-15136 Cookie Banner for GDPR / CCPA – WPLP Cookie Consent <= 4.3.7 - Cross-Site Request Forgery via Bulk Action to Delete/Resolve Entries — WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode CWE-352 4.3 Medium 2026-07-28

This page lists every published CVE security advisory associated with wplegalpages. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.