Executive brief
A security vulnerability exists in the WPLP Cookie Consent plugin for WordPress, which is used to manage legal compliance banners on websites. An attacker with administrative access can exploit this flaw to run unauthorized database commands. This could lead to the theft of sensitive information stored in the website's database, potentially compromising user data or site configuration.
Technical details
The WPLP Cookie Consent plugin for WordPress is vulnerable to a generic SQL Injection vulnerability due to insufficient escaping of the 'scan_id' parameter and a lack of SQL query preparation. The flaw exists in the cookie scanner module, specifically within administrative and AJAX-based functions. An authenticated attacker with administrator-level privileges can inject malicious SQL fragments into existing queries. This can be leveraged to extract sensitive data from the WordPress database. The vulnerability affects all versions up to and including 4.3.6; users should update to the latest patched version.
Affected products
- WPLegalPages Cookie Banner for GDPR / CCPA – WPLP Cookie Consent Up to and including 4.3.6
Timeline
- 2026-07-10: disclosed: CVE published to the NVD dataset
- 2026-07-10: advisory: Wordfence published vulnerability details
References
- https://plugins.trac.wordpress.org/browser/gdpr-cookie-consent/tags/4.3.6/admin/modules/cookie-scanner/class-wpl-cookie-consent-cookie-scanner.php
- https://plugins.trac.wordpress.org/browser/gdpr-cookie-consent/tags/4.3.6/admin/modules/cookie-scanner/class-wpl-cookie-consent-cookie-scanner.php
- https://plugins.trac.wordpress.org/browser/gdpr-cookie-consent/tags/4.3.6/admin/modules/cookie-scanner/classes/class-wpl-cookie-consent-cookie-scanner-ajax.php
- https://plugins.trac.wordpress.org/browser/gdpr-cookie-consent/tags/4.3.6/admin/modules/cookie-scanner/classes/class-wpl-cookie-consent-cookie-scanner-ajax.php
- https://plugins.trac.wordpress.org/browser/gdpr-cookie-consent/tags/4.3.6/admin/modules/cookie-scanner/classes/class-wpl-cookie-consent-cookie-scanner-ajax.php
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3601475%40gdpr-cookie-consent&new=3601475%40gdpr-cookie-consent
- https://www.wordfence.com/threat-intel/vulnerabilities/id/376741ee-9b6b-4822-8bad-548e212cd563?source=cve