The WPLP Cookie Consent plugin for WordPress is vulnerable to arbitrary file upload in all versions up to and including 4.4.1. The vulnerability stems from missing file type validation in the saas_upload_logo() function combined with an authorization bypass on WPLP connector REST endpoints. Unauthenticated attackers can exploit this flaw to upload arbitrary files to the affected server. Successful exploitation may lead to remote code execution. No authentication is required, making this a critical risk for any WordPress site running the affected plugin versions. The vulnerability affects the plugin used for GDPR, CCPA, and Google Consent Mode cookie banner management. A patch is available via the WordPress plugin repository changeset 3674117. The issue is tracked as CVE-2026-75865 and documented by both NVD and Wordfence.