Executive brief
The WPLP Cookie Consent WordPress plugin before version 4.4.2 contains a SQL injection vulnerability in its pagination handling. An attacker with administrator-level access can exploit improper validation of the offset parameter to execute arbitrary database queries, potentially exposing sensitive WordPress data including user credentials and site configuration.
Technical details
The plugin fails to properly sanitize the pagination offset parameter before incorporating it into a SQL query. The vulnerability is exploitable via the wpl_cookie_scanner AJAX action when a valid administrator nonce is obtained. An authenticated attacker with administrator privileges can inject arbitrary SQL commands through the offset parameter using time-based blind SQL injection techniques to extract data bit-by-bit from the WordPress database. The fix was released in version 4.4.2.
Affected products
- WPLP Cookie Consent before 4.4.2
Timeline
- 2026-09-02: disclosed
- 2026-09-02: patched: Fixed in version 4.4.2