---
id: CVE-2026-85130
title: >-
  The WPLP Cookie Consent  WordPress plugin before 4.4.4 does not escape a value
  submitted through a public endpoint for the JavaScript context it is later
  output in on an administrative screen, allowing unauthenticated users to run
  arbitr…
summary: >-
  The WPLP Cookie Consent  WordPress plugin before 4.4.4 does not escape a value
  submitted through a public endpoint for the JavaScript context it is later
  output in on an administrative screen, allowing unauthenticated users to run
  arbitr…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-79
product: WPLP Cookie Consent
affected:
  - wplp_cookie_consent < 4.4.4
published: '2026-09-17'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:08:32.830'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85130'
references:
  - url: 'https://wpscan.com/vulnerability/e48e363f-17e5-4b78-90b3-824c0bc47a23/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
epss: 0.00505
epssPercentile: 0.40582
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-17T12:14:02.299175Z'
ingestedAt: '2026-09-17T06:12:17.976Z'
---

## Overview

The WPLP Cookie Consent  WordPress plugin before 4.4.4 does not escape a value submitted through a public endpoint for the JavaScript context it is later output in on an administrative screen, allowing unauthenticated users to run arbitrary JavaScript in the session of an administrator who interacts with the logged entry. Only multisite installations are affected.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
