CVE-2026-75865
—Unauthenticated Arbitrary File Upload to RCE in WPLP Cookie Consent WordPress Plugin
The WPLP Cookie Consent plugin for WordPress, in all versions up to and including 4.4.1, combines missing file type validation in its saas_upload_logo() function with an authorization bypass on the WPLP connector REST endpoints. Because those REST routes require no authentication, an unauthenticated attacker can send a crafted request that uploads an arbitrary file, such as a PHP file, to the affected site's server. Depending on where the file lands and how the server is configured, this can lead to remote code execution and full site compromise, consistent with the 9.8 CVSS score. Any WordPress site running WPLP Cookie Consent version 4.4.1 or earlier is exposed. As of this analysis there is no public proof of concept, the flaw is not in CISA's KEV, and its EPSS of 0.5% (42nd percentile) suggests a low probability of near-term exploitation.
What to do: Update the WPLP Cookie Consent plugin as soon as a patched release beyond 4.4.1 becomes available. Until patched, deactivate the plugin or block unauthenticated access to its connector REST endpoints (e.g., via WAF or server rules restricting REST access), and review the uploads directory and web root for unexpected PHP files that could indicate prior exploitation.
| WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode (WordPress plugin) | All versions up to and including 4.4.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the saas_upload_logo() function combined with an authorization bypass on the WPLP connector REST endpoints in all versions up to, and including, 4.4.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
- Ecosystems
- WordPress
- Weakness
- CWE-434
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.