SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-82184

MEDIUM · CVSS 5.3 EPSS 0.11%

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The WPLP Cookie Consent plugin for WordPress versions prior to 4.4.2 is vulnerable due to the absence of authorization and CSRF checks when managing visitor consent states, enabling unauthenticated attackers to modify site-wide options with arbitrary data on each front-end page load. This flaw poses a risk of unauthorized changes to site configurations, potentially leading to further exploitation or data integrity issues. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this vulnerability.

CVE
CVE-2026-82184
Severity
MEDIUM
CVSS
5.3
EPSS
0.11%
WordPress

Original NVD Description

The WPLP Cookie Consent WordPress plugin before 4.4.2 does not have any authorisation or CSRF checks when storing visitor consent state, and the code that does so runs on every front-end page load, allowing unauthenticated attackers to overwrite a site-wide option with arbitrary data.