Junglewise Threat Intelligence

CVE-2026-82970: WP Cookie Notice for GDPR unrestricted file upload vulnerability

CVE-2026-82970 · Severity: critical · CVSS 10 · Published 2026-08-31

Executive brief

WP Cookie Notice for GDPR, CCPA & ePrivacy Consent is a widely-used WordPress plugin that manages cookie consent banners for regulatory compliance. An unrestricted file upload flaw allows attackers to upload malicious files to affected websites without authentication, potentially leading to complete server compromise and takeover.

Technical details

This vulnerability is an unrestricted file upload flaw (CWE-434) in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin versions through 4.4.1. The vulnerability allows unauthenticated attackers to upload arbitrary files with dangerous types to the web server. The attack requires no user interaction or prior authentication, making it exploitable over the network. Successful exploitation enables remote code execution and complete server takeover. The vulnerability has been patched in version 4.4.2 and later.

Affected products

  • WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent through 4.4.1

Timeline

  • 2026-08-31: disclosed: Vulnerability published by Patchstack
  • 2026-08-31: patched: Patched in version 4.4.2
  • 2026-07-18: other: Vulnerability reported

References