CVE-2026-82970
10.0WP Legal Pages · WP Cookie Notice for GDPR, CCPA & ePrivacy Consent
A critical unrestricted file upload vulnerability in the WP Cookie Notice plugin allows unauthenticated attackers to upload and execute arbitrary malicious files.
Executive summary
A critical, unauthenticated file upload vulnerability in the WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin allows remote attackers to achieve full system compromise.
Vulnerability
This flaw is an unrestricted upload of a file with a dangerous type (CWE-434). It allows an unauthenticated remote attacker to bypass file validation and upload malicious content, which can lead to remote code execution.
Business impact
The ability to upload arbitrary files without authentication poses a catastrophic risk to the integrity and confidentiality of the entire WordPress environment. Given the CVSS score of 10.0, this vulnerability provides attackers with total control over the web server, potentially facilitating data exfiltration, site defacement, or the deployment of persistent backdoors within the organization's infrastructure.
Remediation
Immediate Action: Update the WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin to version 4.4.2 or higher immediately.
Proactive Monitoring: Monitor web server access logs for suspicious POST requests targeting plugin directories or unusual file extensions being uploaded to the server.
Compensating Controls: Deploy a Web Application Firewall (WAF) with strict rulesets to block unauthorized file uploads and filter malicious payloads targeting known vulnerable parameters.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Due to the critical severity of this vulnerability and the potential for complete system compromise, administrators must prioritize patching this plugin immediately. Organizations unable to update at this time should consider deactivating the plugin until a secure version is successfully deployed to prevent unauthorized access.
More WP Legal Pages CVEs
Sources
Originally found and disclosed by Jiemook | Patchstack Bug Bounty Program, per the CVE Program record.