Junglewise Threat Intelligence

CVE-2026-12920: wplegalpages WPLP Cookie Consent SQL injection in s parameter

CVE-2026-12920 · Severity: medium · CVSS 4.9 · Published 2026-07-03

Technologies: WPLegalPages Cookie Banner for GDPR / CCPA – WPLP Cookie Consent. Vendors: WPLegalPages.

Executive brief

The WPLP Cookie Consent plugin for WordPress, which helps websites comply with privacy regulations like GDPR and CCPA, contains a security flaw. An attacker with administrator-level access could exploit this vulnerability to run unauthorized database commands. This could allow them to extract sensitive information from the website's database, potentially compromising user data or site configuration.

Technical details

The WPLP Cookie Consent plugin for WordPress is vulnerable to a generic SQL Injection via the 's' parameter in all versions up to, and including, 4.3.5. The vulnerability stems from insufficient escaping of user-supplied input and a lack of proper preparation of the SQL query within the 'class-wpl-data-req-table.php' component. An authenticated attacker with administrator-level privileges can append additional SQL queries to existing ones. This enables the extraction of sensitive data from the WordPress database. The issue has been addressed in subsequent updates via improved input sanitization and query preparation.

Affected products

  • wplegalpages Cookie Banner for GDPR / CCPA – WPLP Cookie Consent up to, and including, 4.3.5

Timeline

  • 2026-07-03: advisory: NVD publication date
  • 2026-07-02: disclosed: Wordfence disclosure date

References

Related threats