CRITICAL 9.8 CVE-2026-75865 Published 1 Sept 2026

WordPress WPLP Cookie Consent Arbitrary File Upload

Worried this affects your website?

The WPLP Cookie Consent plugin for WordPress is vulnerable. An unauthenticated attacker can upload arbitrary files to the affected site's server due to missing file type validation and an authorization bypass in the REST API.

This vulnerability affects all versions up to and including 4.4.1.

Exploitation of this issue may allow remote code execution.

Reference: CVE-2026-75865 on NVD

← Back to Security News