---
id: CVE-2026-82184
title: >-
  The WPLP Cookie Consent  WordPress plugin before 4.4.2 does not have any
  authorisation or CSRF checks when storing visitor consent state, and the code
  that does so runs on every front-end page load, allowing unauthenticated
  attackers to …
summary: >-
  The WPLP Cookie Consent  WordPress plugin before 4.4.2 does not have any
  authorisation or CSRF checks when storing visitor consent state, and the code
  that does so runs on every front-end page load, allowing unauthenticated
  attackers to …
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-862
  - CWE-352
product: WPLP Cookie Consent
affected:
  - wplp_cookie_consent >= 3.5.0 < 4.4.2
published: '2026-09-09'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T16:17:11.140'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82184'
references:
  - url: 'https://wpscan.com/vulnerability/54f2da44-84c2-4c56-88f3-615ae4054ecb/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-09T15:33:16.485406Z'
epss: 0.00163
epssPercentile: 0.04833
ingestedAt: '2026-09-09T07:03:03.592Z'
---

## Overview

The WPLP Cookie Consent  WordPress plugin before 4.4.2 does not have any authorisation or CSRF checks when storing visitor consent state, and the code that does so runs on every front-end page load, allowing unauthenticated attackers to overwrite a site-wide option with arbitrary data.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
