CVE-2026-82970
largeUnauthenticated File Upload in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent
CVE-2026-82970 is an unrestricted upload of files with dangerous types (CWE-434) in the WP Legal Pages plugin 'WP Cookie Notice for GDPR, CCPA & ePrivacy Consent', affecting every version of the plugin through 4.4.1. The plugin's file-upload functionality does not properly validate or restrict uploaded file types, and the CVSS 3.1 vector (network attack vector, low complexity, no privileges required, no user interaction) indicates an unauthenticated attacker can trigger it remotely with a crafted upload request. Because files of dangerous types (e.g., executable script files) can be placed on the server, successful exploitation could enable remote code execution and full site compromise, consistent with the critical 10.0 score and the scope-changed, high-impact ratings. Any WordPress site with this plugin active at version 4.4.1 or earlier is affected. There is currently no public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns a 0.3% probability of exploitation within 30 days, so no confirmed exploitation is known.
What to do: Upgrade the plugin to a release newer than 4.4.1 as soon as a patched version is published (check the WordPress.org plugin page or vendor changelog, since the advisory does not name the fixed version). Until patched, deactivate the plugin or block unauthenticated requests to its upload endpoints with a WAF, and review wp-content/uploads and the plugin's directories for unexpected .php or other executable files that could indicate prior exploitation.
| WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent (WordPress plugin) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unrestricted Upload of File with Dangerous Type vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent allows Using Malicious Files. This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through 4.4.1.
- Ecosystems
- WordPress
- Weakness
- CWE-434
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.