Executive brief
The WPLP Cookie Consent WordPress plugin is a tool that manages website visitor cookie preferences and consent compliance. The plugin fails to properly authorize AJAX actions, allowing any logged-in subscriber to read sensitive scan data, modify plugin configuration, and inject arbitrary content into banner settings that all site visitors see. An attacker with basic subscriber access can deface cookie banners, erase admin audit data, and disrupt consent management operations.
Technical details
The vulnerability is a missing authorization (broken access control) flaw in multiple AJAX action handlers within the WPLP Cookie Consent WordPress plugin before version 4.4.2. The affected handlers (gcc_clear_schedule_scan, wpl_get_gcm_status, gcc_enable_iab, ab_testing_enable, wpl_script_add) perform no nonce validation or capability checks, only checking for basic WordPress authentication. An attacker with a subscriber account—the lowest privilege WordPress role—can POST to these handlers and read administrator configuration, delete admin-owned scan schedules, overwrite vendor datasets, modify banner content displayed to all site visitors, and manipulate whitelist settings. No special preconditions or user interaction are required. The vendor released version 4.4.2 to address this issue.
Affected products
- WPLP Cookie Consent before 4.4.2
Timeline
- 2026-09-07: disclosed
- 2026-09-09: patched