[CVE-2026-75865] The WPLP Cookie Consent – Cookie Banner & Consent Management

CVE-2026-75865 | CVSS: 9.8 | 严重级别: CRITICAL

The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the saas_upload_logo() function combined with an authorization bypass on the WPLP connector REST endpoints in all versions up to, and including, 4.4.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

参考链接:
https://plugins.trac.wordpress.org/changeset/3674117/gdpr-cookie-consent
https://www.wordfence.com/threat-intel/vulnerabilities/id/96a2a552-e73f-4b27-88d

📌 数据来源: NVD 官方

⚠️ 合规声明: 本文内容仅用于网络安全合规学习、科研与授权测试用途。严禁用于任何未授权行为,违者自行承担全部法律责任。
滚动至顶部