SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-82186

MEDIUM · CVSS 4.1 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The WPLP Cookie Consent plugin for WordPress versions prior to 4.4.2 is vulnerable to SQL injection due to inadequate validation of a pagination parameter, which could be exploited by users with administrator privileges. Successful exploitation may allow attackers to manipulate the database, potentially leading to data leakage or unauthorized data modification. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-82186
Severity
MEDIUM
CVSS
4.1
EPSS
0.19%
WordPress

Original NVD Description

The WPLP Cookie Consent WordPress plugin before 4.4.2 does not properly validate a pagination parameter before using it in a SQL query, allowing users with administrator privileges to perform SQL injection attacks.