← العودة للجدول
CVE-2026-75865
CVE-2026-75865 — The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCP
📅 2026-09-01
🔴 Critical 🔥 No NVD Vulnerability WordPress CVSS 9.8

📋 الوصف الكامل

The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the saas_upload_logo() function combined with an authorization bypass on the WPLP connector REST endpoints in all versions up to, and including, 4.4.1. This makes it possible for unauthenticate

💻 الأنظمة المتأثرة

WordPress

⚠️ نوع التهديد

Vulnerability

🔗 CVE ID

CVE-2026-75865

📡 المصدر

NVD

✅ الحلول والتخفيف

Update to v4.4.1

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ← 🔍 Valters IT ←