← Back to overview

A critical Unrestricted Upload of File with Dangerous Type vulnerability has been identified in the WP Cookie Notice for GDPR, CCPA & ePrivacy Consent WordPress plugin by WP Legal Pages. The vulnerability affects all versions up to and including 4.4.1. Exploitation of this flaw allows attackers to upload malicious files to the affected WordPress installation. This type of vulnerability can lead to remote code execution, full site compromise, or deployment of web shells. The issue is tracked as CVE-2026-82970 and has been published by both NVD/NIST and Patchstack. WordPress site administrators using this plugin are advised to update to a patched version immediately. No workaround details are provided beyond patching.

Affected products

  • CCPA & ePrivacy Consent (up to 4.4.1)
  • WP Cookie Notice for GDPR

Related CVE's

  • CVE-2026-82970

Categories

  • Web Technologies