Junglewise Threat Intelligence

CVE-2026-85132: WPLP Cookie Consent privilege escalation in AJAX handler

CVE-2026-85132 · Severity: medium · CVSS 4.3 · Published 2026-09-09

Executive brief

WPLP Cookie Consent is a WordPress plugin that helps manage cookie consent settings and scan for cookies on a website. A flaw in the plugin allows any logged-in user (including low-privilege accounts like subscribers) to read the administrator's automated cookie scan schedule, which may contain sensitive timing information about site operations. This vulnerability could be exploited by insiders or account-compromised users to gather operational intelligence.

Technical details

The vulnerability is a missing authorization check (CWE-862) in the AJAX handler for the gcc_get_schedule_scan action. The plugin fails to validate either a nonce token or the user's capability (administrator role) before returning the configured scan schedule. An authenticated attacker with minimal privileges (e.g., subscriber role) can call the action via wp-admin/admin-ajax.php and retrieve the schedule data in JSON format. The sibling handler gcc_save_schedule_scan correctly performs these checks, confirming this is an oversight rather than a design choice. The vulnerability affects versions 4.0.2 through 4.4.1 and is fixed in version 4.4.2.

Affected products

  • Karthik Ramakrishnan WPLP Cookie Consent 4.0.2 to 4.4.1

Timeline

  • 2026-09-07: disclosed
  • 2026-09-09: patched: Fixed in version 4.4.2

References