CVE-2026-85132 The WPLP Cookie Consent WordPress plugin before 4.4.2… — CVE Notify — TG.ME

🚨 CVE-2026-85132
The WPLP Cookie Consent WordPress plugin before 4.4.2 does not perform nonce or capability checks on one of its cookie scanner AJAX actions, allowing any authenticated user, such as a subscriber, to read back the automated scan schedule the administrator configured.

🎖@cveNotify
WPScan
WPLP Cookie Consent 4.0.2 - 4.4.1 - Subscriber+ Cookie Scan Schedule Disclosure via gcc_get_schedule_scan
See details on WPLP Cookie Consent 4.0.2 - 4.4.1 - Subscriber+ Cookie Scan Schedule Disclosure via gcc_get_schedule_scan CVE 2026-85132. View the latest Plugin Vulnerabilities on WPScan.
September 9, 2026 28