---
id: CVE-2026-85131
title: >-
  The WPLP Cookie Consent  WordPress plugin before 4.4.4 does not perform CSRF
  or capability checks when processing bulk actions on its administration
  screens, and does not restrict the targeted items to its own records, allowing
  attackers…
summary: >-
  The WPLP Cookie Consent  WordPress plugin before 4.4.4 does not perform CSRF
  or capability checks when processing bulk actions on its administration
  screens, and does not restrict the targeted items to its own records, allowing
  attackers…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'
cwe:
  - CWE-352
product: WPLP Cookie Consent
affected:
  - wplp_cookie_consent < 4.4.4
published: '2026-09-16'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T13:16:50.623'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85131'
references:
  - url: 'https://wpscan.com/vulnerability/5a94c9c8-5b30-4735-be6b-ced53ff587bc/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-17T12:19:36.574145Z'
epss: 0.00181
epssPercentile: 0.07927
ingestedAt: '2026-09-16T06:51:06.250Z'
---

## Overview

The WPLP Cookie Consent  WordPress plugin before 4.4.4 does not perform CSRF or capability checks when processing bulk actions on its administration screens, and does not restrict the targeted items to its own records, allowing attackers to make a logged in admin permanently delete arbitrary posts and pages via a crafted request.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
