Executive brief
WPLP Cookie Consent is a WordPress plugin that manages visitor cookie consent via a cookie banner. The plugin fails to validate user identity or session tokens when processing consent updates, allowing anyone to remotely change consent settings for all site visitors. An attacker can inject malicious consent data that will be served to every visitor, potentially leading to tracking bypasses or other consent-related compromises.
Technical details
The vulnerability is a missing authorization check (CWE-862) in the IAB TCF consent data update mechanism. The vulnerable code runs on every front-end page load without validating CSRF tokens or user authentication. An unauthenticated attacker can send a POST request to any front-end URL with arbitrary consent data (tcString, allVendorsSelected, allvendorIds) which is then stored as a site-wide WordPress option and served to all visitors. The cookie banner is enabled by default and no additional prerequisites are needed to exploit this. Proof-of-concept code demonstrates reading current values from page source and overwriting them with injected data in a single unauthenticated POST request. The vulnerability is fixed in version 4.4.2.
Affected products
- WPLP Cookie Consent before 4.4.2
Timeline
- 2026-09-07: disclosed
- 2026-09-07: patched: Fixed in version 4.4.2