Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-82970: WP Cookie Notice plugin lets attackers upload malicious files
CVE-2026-82970 · published 3 days ago
Summary
The WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin (versions up to 4.4.1) allows anyone to upload a file of any type. An attacker could place a malicious script on your WordPress site, giving them control or access to data. Update the plugin to the latest version or replace it with a secure alternative as soon as possible.
What to do
- Update wp legal pages wp cookie notice for gdpr, ccpa & eprivacy consent to version 4.4.2.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| wp legal pages | wp cookie notice for gdpr, ccpa & eprivacy consent |
<= 4.4.1 Fix: upgrade to 4.4.2
|
Original advisory text
WordPress WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin <= 4.4.1 - Arbitrary File Upload vulnerability
Unrestricted Upload of File with Dangerous Type vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent allows Using Malicious Files.
This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through 4.4.1.
This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through 4.4.1.
Severity
10.0
Critical
CVSS 3.1: 10.0 (NVD)
Exploitation
EPSS <1%
Type
CWE-434Unrestricted File Upload
Timeline
Published31 Aug 2026
Updated2 Sep 2026
First seen31 Aug 2026
Monitor software like this
Free during beta