{"schema_version":1,"title":"WebToffee Cookie Consent vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 11 vulnerabilities in WebToffee Cookie Consent: 0 in the last 7 days and 11 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-85130, was published on 17 September 2026.","url":"https://junglewise.ai/threats/technologies/cookie-consent","json_url":"https://junglewise.ai/threats/technologies/cookie-consent.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/cookie-consent","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":3,"all_time":11,"critical":1,"exploited":0,"last_7_days":0,"last_30_days":7,"last_90_days":11,"last_365_days":11},"latest":[{"cve":"CVE-2026-85130","cvss":8.8,"epss":0.0051,"slug":"cve-2026-85130-wplp-cookie-consent-stored-xss-via-consent-logs","title":"WPLP Cookie Consent stored XSS via consent logs","severity":"high","exploited":false,"published_at":"2026-09-17T06:16:50.99+00:00","url":"https://junglewise.ai/threats/cve-2026-85130-wplp-cookie-consent-stored-xss-via-consent-logs"},{"cve":"CVE-2026-85131","cvss":6.5,"epss":0.002,"slug":"cve-2026-85131-wplp-cookie-consent-arbitrary-post-deletion-via-csrf","title":"WPLP Cookie Consent arbitrary post deletion via CSRF","severity":"medium","exploited":false,"published_at":"2026-09-16T06:16:33.94+00:00","url":"https://junglewise.ai/threats/cve-2026-85131-wplp-cookie-consent-arbitrary-post-deletion-via-csrf"},{"cve":"CVE-2026-14989","cvss":7.2,"epss":0.0028,"slug":"cve-2026-14989-wplp-cookie-consent-stored-cross-site-scripting-via-wpl-user","title":"WPLP Cookie Consent stored cross-site scripting via wpl_user_preference","severity":"high","exploited":false,"published_at":"2026-09-09T09:17:10.58+00:00","url":"https://junglewise.ai/threats/cve-2026-14989-wplp-cookie-consent-stored-cross-site-scripting-via-wpl-user"},{"cve":"CVE-2026-85133","cvss":5.4,"epss":0.0023,"slug":"cve-2026-85133-wplp-cookie-consent-privilege-escalation-via-missing","title":"WPLP Cookie Consent privilege escalation via missing authorization checks","severity":"medium","exploited":false,"published_at":"2026-09-09T06:17:18.497+00:00","url":"https://junglewise.ai/threats/cve-2026-85133-wplp-cookie-consent-privilege-escalation-via-missing"},{"cve":"CVE-2026-82184","cvss":5.3,"epss":0.0016,"slug":"cve-2026-82184-wplp-cookie-consent-authorization-bypass-in-consent-option-update","title":"WPLP Cookie Consent authorization bypass in consent option update","severity":"medium","exploited":false,"published_at":"2026-09-09T06:17:17.257+00:00","url":"https://junglewise.ai/threats/cve-2026-82184-wplp-cookie-consent-authorization-bypass-in-consent-option-update"},{"cve":"CVE-2026-82186","cvss":4.1,"epss":0.0031,"slug":"cve-2026-82186-wplp-cookie-consent-plugin-sql-injection-via-offset-parameter","title":"WPLP Cookie Consent plugin SQL injection via offset parameter","severity":"medium","exploited":false,"published_at":"2026-09-04T07:17:10.647+00:00","url":"https://junglewise.ai/threats/cve-2026-82186-wplp-cookie-consent-plugin-sql-injection-via-offset-parameter"},{"cve":"CVE-2026-75865","cvss":9.8,"epss":0.0092,"slug":"cve-2026-75865-wplp-cookie-consent-arbitrary-file-upload-and-auth-bypass","title":"WPLP Cookie Consent arbitrary file upload and auth bypass","severity":"critical","exploited":false,"published_at":"2026-09-01T03:16:51.37+00:00","url":"https://junglewise.ai/threats/cve-2026-75865-wplp-cookie-consent-arbitrary-file-upload-and-auth-bypass"},{"cve":"CVE-2026-13360","cvss":7.2,"epss":0.0043,"slug":"cve-2026-13360-wplp-cookie-consent-plugin-stored-cross-site-scripting-in","title":"WPLP Cookie Consent plugin stored cross-site scripting in regionArray parameter","severity":"high","exploited":false,"published_at":"2026-08-15T04:18:01.957+00:00","url":"https://junglewise.ai/threats/cve-2026-13360-wplp-cookie-consent-plugin-stored-cross-site-scripting-in"},{"cve":"CVE-2026-18046","cvss":4.3,"epss":0.0031,"slug":"cve-2026-18046-cookie-consent-wordpress-plugin-privilege-escalation-in-rest-api","title":"Cookie Consent WordPress plugin privilege escalation in REST API","severity":"medium","exploited":false,"published_at":"2026-08-12T06:19:22.783+00:00","url":"https://junglewise.ai/threats/cve-2026-18046-cookie-consent-wordpress-plugin-privilege-escalation-in-rest-api"},{"cve":"CVE-2026-15388","cvss":4.3,"epss":0.0033,"slug":"cve-2026-15388-wordpress-cookie-consent-privilege-escalation-in-rest-api","title":"WordPress Cookie Consent privilege escalation in REST API","severity":"medium","exploited":false,"published_at":"2026-08-12T06:18:09.547+00:00","url":"https://junglewise.ai/threats/cve-2026-15388-wordpress-cookie-consent-privilege-escalation-in-rest-api"},{"cve":"CVE-2026-13389","cvss":6.5,"epss":0.003,"slug":"cve-2026-13389-webtoffee-cookie-consent-authorization-bypass-in-rest-api","title":"WebToffee Cookie Consent authorization bypass in REST API","severity":"medium","exploited":false,"published_at":"2026-08-02T06:16:34.55+00:00","url":"https://junglewise.ai/threats/cve-2026-13389-webtoffee-cookie-consent-authorization-bypass-in-rest-api"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":1,"exploited":0,"vulnerabilities":2},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[],"technology":{"hub":true,"name":"WebToffee Cookie Consent","slug":"cookie-consent","vendor":{"name":"WebToffee","slug":"webtoffee","url":"https://junglewise.ai/threats/vendors/webtoffee"},"aliases":[],"category":"wordpress-plugin","url":"https://junglewise.ai/threats/technologies/cookie-consent"},"most_severe":[{"cve":"CVE-2026-75865","cvss":9.8,"epss":0.0092,"slug":"cve-2026-75865-wplp-cookie-consent-arbitrary-file-upload-and-auth-bypass","title":"WPLP Cookie Consent arbitrary file upload and auth bypass","severity":"critical","exploited":false,"published_at":"2026-09-01T03:16:51.37+00:00","url":"https://junglewise.ai/threats/cve-2026-75865-wplp-cookie-consent-arbitrary-file-upload-and-auth-bypass"},{"cve":"CVE-2026-85130","cvss":8.8,"epss":0.0051,"slug":"cve-2026-85130-wplp-cookie-consent-stored-xss-via-consent-logs","title":"WPLP Cookie Consent stored XSS via consent logs","severity":"high","exploited":false,"published_at":"2026-09-17T06:16:50.99+00:00","url":"https://junglewise.ai/threats/cve-2026-85130-wplp-cookie-consent-stored-xss-via-consent-logs"},{"cve":"CVE-2026-13360","cvss":7.2,"epss":0.0043,"slug":"cve-2026-13360-wplp-cookie-consent-plugin-stored-cross-site-scripting-in","title":"WPLP Cookie Consent plugin stored cross-site scripting in regionArray parameter","severity":"high","exploited":false,"published_at":"2026-08-15T04:18:01.957+00:00","url":"https://junglewise.ai/threats/cve-2026-13360-wplp-cookie-consent-plugin-stored-cross-site-scripting-in"},{"cve":"CVE-2026-14989","cvss":7.2,"epss":0.0028,"slug":"cve-2026-14989-wplp-cookie-consent-stored-cross-site-scripting-via-wpl-user","title":"WPLP Cookie Consent stored cross-site scripting via wpl_user_preference","severity":"high","exploited":false,"published_at":"2026-09-09T09:17:10.58+00:00","url":"https://junglewise.ai/threats/cve-2026-14989-wplp-cookie-consent-stored-cross-site-scripting-via-wpl-user"},{"cve":"CVE-2026-13389","cvss":6.5,"epss":0.003,"slug":"cve-2026-13389-webtoffee-cookie-consent-authorization-bypass-in-rest-api","title":"WebToffee Cookie Consent authorization bypass in REST API","severity":"medium","exploited":false,"published_at":"2026-08-02T06:16:34.55+00:00","url":"https://junglewise.ai/threats/cve-2026-13389-webtoffee-cookie-consent-authorization-bypass-in-rest-api"},{"cve":"CVE-2026-85131","cvss":6.5,"epss":0.002,"slug":"cve-2026-85131-wplp-cookie-consent-arbitrary-post-deletion-via-csrf","title":"WPLP Cookie Consent arbitrary post deletion via CSRF","severity":"medium","exploited":false,"published_at":"2026-09-16T06:16:33.94+00:00","url":"https://junglewise.ai/threats/cve-2026-85131-wplp-cookie-consent-arbitrary-post-deletion-via-csrf"},{"cve":"CVE-2026-85133","cvss":5.4,"epss":0.0023,"slug":"cve-2026-85133-wplp-cookie-consent-privilege-escalation-via-missing","title":"WPLP Cookie Consent privilege escalation via missing authorization checks","severity":"medium","exploited":false,"published_at":"2026-09-09T06:17:18.497+00:00","url":"https://junglewise.ai/threats/cve-2026-85133-wplp-cookie-consent-privilege-escalation-via-missing"},{"cve":"CVE-2026-82184","cvss":5.3,"epss":0.0016,"slug":"cve-2026-82184-wplp-cookie-consent-authorization-bypass-in-consent-option-update","title":"WPLP Cookie Consent authorization bypass in consent option update","severity":"medium","exploited":false,"published_at":"2026-09-09T06:17:17.257+00:00","url":"https://junglewise.ai/threats/cve-2026-82184-wplp-cookie-consent-authorization-bypass-in-consent-option-update"},{"cve":"CVE-2026-15388","cvss":4.3,"epss":0.0033,"slug":"cve-2026-15388-wordpress-cookie-consent-privilege-escalation-in-rest-api","title":"WordPress Cookie Consent privilege escalation in REST API","severity":"medium","exploited":false,"published_at":"2026-08-12T06:18:09.547+00:00","url":"https://junglewise.ai/threats/cve-2026-15388-wordpress-cookie-consent-privilege-escalation-in-rest-api"},{"cve":"CVE-2026-18046","cvss":4.3,"epss":0.0031,"slug":"cve-2026-18046-cookie-consent-wordpress-plugin-privilege-escalation-in-rest-api","title":"Cookie Consent WordPress plugin privilege escalation in REST API","severity":"medium","exploited":false,"published_at":"2026-08-12T06:19:22.783+00:00","url":"https://junglewise.ai/threats/cve-2026-18046-cookie-consent-wordpress-plugin-privilege-escalation-in-rest-api"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}