← Terug naar overzicht

The WPLP Cookie Consent plugin for WordPress (versions up to and including 4.4.1) contains a critical vulnerability allowing unauthenticated arbitrary file uploads. The flaw stems from missing file type validation in the saas_upload_logo() function combined with an authorization bypass on the WPLP connector REST endpoints. Unauthenticated attackers can exploit this to upload arbitrary files to the server, potentially leading to remote code execution (RCE). The vulnerability affects all versions up to and including 4.4.1. A patch has been made available via the WordPress plugin repository changeset 3674117. The issue is tracked as CVE-2026-75865 and documented by both NVD and Wordfence. Site administrators running affected versions should update immediately to mitigate the risk of full server compromise.

Affected products

  • WPLP Cookie Consent WordPress Plugin (up to 4.4.1)

Related CVE's

  • CVE-2026-75865

Categories

  • Web Technologies
  • Zero-Day Vulnerabilities