Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-82970: WP Cookie Notice plugin lets attackers upload malicious files

CVE-2026-82970 · published 3 days ago
Summary

The WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin (versions up to 4.4.1) allows anyone to upload a file of any type. An attacker could place a malicious script on your WordPress site, giving them control or access to data. Update the plugin to the latest version or replace it with a secure alternative as soon as possible.

What to do
  • Update wp legal pages wp cookie notice for gdpr, ccpa & eprivacy consent to version 4.4.2.
Affected software
VendorProductAffected versions
wp legal pages wp cookie notice for gdpr, ccpa & eprivacy consent <= 4.4.1
Fix: upgrade to 4.4.2
Original advisory text
WordPress WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin <= 4.4.1 - Arbitrary File Upload vulnerability
Unrestricted Upload of File with Dangerous Type vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent allows Using Malicious Files.

This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through 4.4.1.
Severity
10.0 Critical
CVSS 3.1: 10.0 (NVD)
Exploitation
EPSS <1%
Type
CWE-434Unrestricted File Upload
Timeline
Published31 Aug 2026
Updated2 Sep 2026
First seen31 Aug 2026
Sources
CVE-2026-82970 · MITRE
Monitor software like this
Free during beta