WPLP Cookie Consent < 4.4.4 - Unauthenticated Stored XSS via Consent Logs
Summary
| CVE | CVE-2026-85130 |
|---|---|
| State | PUBLISHED |
| Assigner | WPScan |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-17 06:16:50 UTC |
| Updated | 2026-09-17 06:16:50 UTC |
| Description | The WPLP Cookie Consent WordPress plugin before 4.4.4 does not escape a value submitted through a public endpoint for the JavaScript context it is later output in on an administrative screen, allowing unauthenticated users to run arbitrary JavaScript in the session of an administrator who interacts with the logged entry. Only multisite installations are affected. |
Risk And Classification
Problem Types: CWE-79 Cross-Site Scripting (XSS)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Unknown | WPLP Cookie Consent | affected 4.4.4 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| wpscan.com/vulnerability/e48e363f-17e5-4b78-90b3-824c0bc47a23 | [email protected] | wpscan.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Karthik Ramakrishnan (en)
CNA: WPScan (en)
There are currently no legacy QID mappings associated with this CVE.