WPLP Cookie Consent < 4.4.4 - Arbitrary Post Deletion via CSRF
Summary
| CVE | CVE-2026-85131 |
|---|---|
| State | PUBLISHED |
| Assigner | WPScan |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-16 06:16:33 UTC |
| Updated | 2026-09-16 06:16:33 UTC |
| Description | The WPLP Cookie Consent WordPress plugin before 4.4.4 does not perform CSRF or capability checks when processing bulk actions on its administration screens, and does not restrict the targeted items to its own records, allowing attackers to make a logged in admin permanently delete arbitrary posts and pages via a crafted request. |
Risk And Classification
Problem Types: CWE-352 Cross-Site Request Forgery (CSRF)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Unknown | WPLP Cookie Consent | affected 4.4.4 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| wpscan.com/vulnerability/5a94c9c8-5b30-4735-be6b-ced53ff587bc | [email protected] | wpscan.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Karthik Ramakrishnan (en)
CNA: WPScan (en)
There are currently no legacy QID mappings associated with this CVE.