Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

wplegalpages — Vulnerabilities & Security Advisories 14

Browse all 14 CVE security advisories affecting wplegalpages. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Wplegalpages is a WordPress plugin designed to help website owners create legal pages and documents. Historically, it has been vulnerable to multiple security issues including cross-site scripting (XSS), remote code execution (RCE), and privilege escalation vulnerabilities. These flaws often stem from insufficient input validation and improper access controls. The plugin has accumulated 9 CVE records, with some vulnerabilities allowing attackers to execute arbitrary code or gain elevated privileges. While no major public incidents have been widely documented, the consistent pattern of security issues across multiple versions indicates ongoing challenges in secure development practices.

Found 2 results / 14Clear Filters
CVE IDTitleCVSSSeverityPublished
CVE-2026-13360 Cookie Banner for GDPR / CCPA <= 4.3.5 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'regionArray' Parameter — WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent ModeCWE-79 7.2 High2026-08-15
CVE-2026-15136 Cookie Banner for GDPR / CCPA – WPLP Cookie Consent <= 4.3.7 - Cross-Site Request Forgery via Bulk Action to Delete/Resolve Entries — WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent ModeCWE-352 4.3 Medium2026-07-28

This page lists every published CVE security advisory associated with wplegalpages. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.