A critical Unrestricted Upload of File with Dangerous Type vulnerability has been identified in the WP Cookie Notice for GDPR, CCPA & ePrivacy Consent WordPress plugin by WP Legal Pages. The vulnerability affects all versions up to and including 4.4.1. Exploitation of this flaw allows attackers to upload malicious files to the affected WordPress installation. This type of vulnerability can lead to remote code execution, full site compromise, or deployment of web shells. The issue is tracked as CVE-2026-82970 and has been published by both NVD/NIST and Patchstack. WordPress site administrators using this plugin are advised to update to a patched version immediately. No workaround details are provided beyond patching.