Executive brief
The WPLP Cookie Consent plugin for WordPress, which helps websites comply with privacy regulations like GDPR and CCPA, contains a security flaw. An attacker with administrator-level access could exploit this vulnerability to run unauthorized database commands. This could allow them to extract sensitive information from the website's database, potentially compromising user data or site configuration.
Technical details
The WPLP Cookie Consent plugin for WordPress is vulnerable to a generic SQL Injection via the 's' parameter in all versions up to, and including, 4.3.5. The vulnerability stems from insufficient escaping of user-supplied input and a lack of proper preparation of the SQL query within the 'class-wpl-data-req-table.php' component. An authenticated attacker with administrator-level privileges can append additional SQL queries to existing ones. This enables the extraction of sensitive data from the WordPress database. The issue has been addressed in subsequent updates via improved input sanitization and query preparation.
Affected products
- wplegalpages Cookie Banner for GDPR / CCPA – WPLP Cookie Consent up to, and including, 4.3.5
Timeline
- 2026-07-03: advisory: NVD publication date
- 2026-07-02: disclosed: Wordfence disclosure date
References
- https://plugins.trac.wordpress.org/browser/gdpr-cookie-consent/tags/4.3.5/admin/data-req/class-wpl-data-req-table.php
- https://plugins.trac.wordpress.org/browser/gdpr-cookie-consent/tags/4.3.5/admin/data-req/class-wpl-data-req-table.php
- https://plugins.trac.wordpress.org/browser/gdpr-cookie-consent/tags/4.3.5/admin/data-req/class-wpl-data-req-table.php
- https://plugins.trac.wordpress.org/browser/gdpr-cookie-consent/tags/4.3.5/admin/data-req/class-wpl-data-req-table.php
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3593450%40gdpr-cookie-consent&new=3593450%40gdpr-cookie-consent&sfp_email=&sfph_mail=
- https://www.wordfence.com/threat-intel/vulnerabilities/id/572bfa82-92f5-4801-8710-0626ca563a6c?source=cve