WORDPRESS · SEPTEMBER 2026 · EARLY WARNING

WPLP Cookie Consent WordPress Plugin Vulnerability: Early Warning

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
CRITICAL
CVSS
9.8
Affected component
wplp cookie consent (wordpress)
Patched version
Not yet available
CVE-2026-75865

An early warning has been issued for a critical vulnerability in the WPLP Cookie Consent WordPress plugin. Versions up to and including 4.4.1 are reportedly affected.

What happened

The WPLP Cookie Consent WordPress plugin, used for GDPR, CCPA, and Google Consent Mode compliance, is under investigation for a critical vulnerability. The issue, tracked as CVE-2026-75865, involves arbitrary file upload due to missing file type validation in the saas_upload_logo() function and an authorization bypass on the WPLP connector REST endpoints. This vulnerability could allow unauthenticated attackers to upload arbitrary files to the affected site's server, potentially enabling remote code execution.

The vulnerability affects all versions of the plugin up to and including 4.4.1. There is no evidence that this vulnerability has been exploited in the wild, but the potential impact is severe due to the possibility of remote code execution.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If wplp cookie consent is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You are affected if your WordPress site is using the WPLP Cookie Consent plugin version 4.4.1 or earlier.

What should I do right now?

Check your plugin version and either upgrade to a fixed version when available or remove the plugin if it is not needed.

Is there a patched version available?

No official fix has been published yet. Monitor the primary sources for updates.

Sources

Join the 0Day waitlist →

← Back to all threats