WPLP Cookie Consent WordPress Plugin Vulnerability: Early Warning
- Severity
- CRITICAL
- CVSS
- 9.8
- Affected component
- wplp cookie consent (wordpress)
- Patched version
- Not yet available
An early warning has been issued for a critical vulnerability in the WPLP Cookie Consent WordPress plugin. Versions up to and including 4.4.1 are reportedly affected.
What happened
The WPLP Cookie Consent WordPress plugin, used for GDPR, CCPA, and Google Consent Mode compliance, is under investigation for a critical vulnerability. The issue, tracked as CVE-2026-75865, involves arbitrary file upload due to missing file type validation in the saas_upload_logo() function and an authorization bypass on the WPLP connector REST endpoints. This vulnerability could allow unauthenticated attackers to upload arbitrary files to the affected site's server, potentially enabling remote code execution.
The vulnerability affects all versions of the plugin up to and including 4.4.1. There is no evidence that this vulnerability has been exploited in the wild, but the potential impact is severe due to the possibility of remote code execution.
What to do about it
- Check if your WordPress site is using the WPLP Cookie Consent plugin version 4.4.1 or earlier.
- If the plugin is in use, upgrade to a version with the fix as soon as it is available. Currently, no official fix has been published yet.
- If the plugin is not needed, remove it from your WordPress site to eliminate the risk.
- Monitor the primary sources for updates on a patched version or further details on the vulnerability.
How 0Day would have caught this
wplp cookie consent is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You are affected if your WordPress site is using the WPLP Cookie Consent plugin version 4.4.1 or earlier.
What should I do right now?
Check your plugin version and either upgrade to a fixed version when available or remove the plugin if it is not needed.
Is there a patched version available?
No official fix has been published yet. Monitor the primary sources for updates.