Executive brief
The WPLP Cookie Consent WordPress plugin before version 4.4.4 contains a security flaw that allows attackers to trick logged-in administrators into permanently deleting any posts or pages on a website. An attacker can craft a malicious request that exploits the plugin's failure to verify user intent or authorization, leading to uncontrolled data loss and potential operational disruption.
Technical details
This is a CSRF (Cross-Site Request Forgery) vulnerability in the plugin's bulk action processing on administration screens. The vulnerable component fails to perform CSRF token validation (nonce checks) or capability/permission verification, and does not restrict bulk operations to the plugin's own records, allowing attackers to target arbitrary posts and pages. An attacker can exploit this by crafting a malicious request (e.g., embedded in a webpage or email) that a logged-in administrator visits, causing the admin's session to execute unauthorized deletion of content. The vulnerability requires the victim to be logged into WordPress but does not require additional authentication. This has been fixed in version 4.4.4.
Affected products
- WPLP Cookie Consent before 4.4.4
Timeline
- 2026-09-14: disclosed
- 2026-09-14: patched: Fixed in version 4.4.4