Executive brief
WPLP Cookie Consent is a WordPress plugin that helps manage cookie consent settings and scan for cookies on a website. A flaw in the plugin allows any logged-in user (including low-privilege accounts like subscribers) to read the administrator's automated cookie scan schedule, which may contain sensitive timing information about site operations. This vulnerability could be exploited by insiders or account-compromised users to gather operational intelligence.
Technical details
The vulnerability is a missing authorization check (CWE-862) in the AJAX handler for the gcc_get_schedule_scan action. The plugin fails to validate either a nonce token or the user's capability (administrator role) before returning the configured scan schedule. An authenticated attacker with minimal privileges (e.g., subscriber role) can call the action via wp-admin/admin-ajax.php and retrieve the schedule data in JSON format. The sibling handler gcc_save_schedule_scan correctly performs these checks, confirming this is an oversight rather than a design choice. The vulnerability affects versions 4.0.2 through 4.4.1 and is fixed in version 4.4.2.
Affected products
- Karthik Ramakrishnan WPLP Cookie Consent 4.0.2 to 4.4.1
Timeline
- 2026-09-07: disclosed
- 2026-09-09: patched: Fixed in version 4.4.2