ZeroHour

CVE-2026-82970

large

Unauthenticated File Upload in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent

CVSS 3.1
10.0 critical
EPSS
<1%p21
Published
()
Modified
AI analysis

CVE-2026-82970 is an unrestricted upload of files with dangerous types (CWE-434) in the WP Legal Pages plugin 'WP Cookie Notice for GDPR, CCPA & ePrivacy Consent', affecting every version of the plugin through 4.4.1. The plugin's file-upload functionality does not properly validate or restrict uploaded file types, and the CVSS 3.1 vector (network attack vector, low complexity, no privileges required, no user interaction) indicates an unauthenticated attacker can trigger it remotely with a crafted upload request. Because files of dangerous types (e.g., executable script files) can be placed on the server, successful exploitation could enable remote code execution and full site compromise, consistent with the critical 10.0 score and the scope-changed, high-impact ratings. Any WordPress site with this plugin active at version 4.4.1 or earlier is affected. There is currently no public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns a 0.3% probability of exploitation within 30 days, so no confirmed exploitation is known.

What to do: Upgrade the plugin to a release newer than 4.4.1 as soon as a patched version is published (check the WordPress.org plugin page or vendor changelog, since the advisory does not name the fixed version). Until patched, deactivate the plugin or block unauthenticated requests to its upload endpoints with a WAF, and review wp-content/uploads and the plugin's directories for unexpected .php or other executable files that could indicate prior exploitation.

Affected
WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent (WordPress plugin)
Estimated exposure
large≈tens of thousands of WordPress sites (order of 10k–100k active installs) — Estimated from public WordPress plugin-directory active-install data, which places this plugin's install base in the tens of thousands; the advisory itself contained no install counts, so this is an order-of-magnitude estimate, not an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unrestricted Upload of File with Dangerous Type vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent allows Using Malicious Files. This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through 4.4.1.

Ecosystems
WordPress
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.