Executive brief
WP Cookie Notice for GDPR, CCPA & ePrivacy Consent is a widely-used WordPress plugin that manages cookie consent banners for regulatory compliance. An unrestricted file upload flaw allows attackers to upload malicious files to affected websites without authentication, potentially leading to complete server compromise and takeover.
Technical details
This vulnerability is an unrestricted file upload flaw (CWE-434) in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin versions through 4.4.1. The vulnerability allows unauthenticated attackers to upload arbitrary files with dangerous types to the web server. The attack requires no user interaction or prior authentication, making it exploitable over the network. Successful exploitation enables remote code execution and complete server takeover. The vulnerability has been patched in version 4.4.2 and later.
Affected products
- WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent through 4.4.1
Timeline
- 2026-08-31: disclosed: Vulnerability published by Patchstack
- 2026-08-31: patched: Patched in version 4.4.2
- 2026-07-18: other: Vulnerability reported