{"id":"CVE-2026-85132","title":"The WPLP Cookie Consent  WordPress plugin before 4.4.2 does not perform nonce or capability checks on one of its cookie scanner AJAX actions, allowing any authenticated user, such as a subscriber, to read back the automated scan schedule…","summary":"The WPLP Cookie Consent  WordPress plugin before 4.4.2 does not perform nonce or capability checks on one of its cookie scanner AJAX actions, allowing any authenticated user, such as a subscriber, to read back the automated scan schedule…","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-862"],"product":"WPLP Cookie Consent","affected":["wplp_cookie_consent >= 4.0.2 < 4.4.2"],"published":"2026-09-09","updated":"2026-09-09","sourceUpdated":"2026-09-09T16:17:13.510","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-85132","references":[{"url":"https://wpscan.com/vulnerability/412f604b-ee33-42b6-8a39-00f7564d4e2b/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-09T15:27:44.230662Z"},"epss":0.0027,"epssPercentile":0.17136,"ingestedAt":"2026-09-09T07:03:03.595Z","slug":"CVE-2026-85132","body":"## Overview\n\nThe WPLP Cookie Consent  WordPress plugin before 4.4.2 does not perform nonce or capability checks on one of its cookie scanner AJAX actions, allowing any authenticated user, such as a subscriber, to read back the automated scan schedule the administrator configured.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":19684,"id":"CVE-2026-85132","ts":1788970490436,"field":"cvss","old":null,"new":"4.3"},{"seq":19683,"id":"CVE-2026-85132","ts":1788970490436,"field":"severity","old":"none","new":"medium"}]}