CVE-2026-82186: Unknown Wplp Cookie Consent

Medium severity, CVSS 4.1. EPSS: 0.3% chance of exploitation in the next 30 days.

The WPLP Cookie Consent WordPress plugin before 4.4.2 does not properly validate a pagination parameter before using it in a SQL query, allowing users with administrator privileges to perform SQL injection attacks.

Affected products

  • Unknown Wplp Cookie Consent: from 3.0.0, before 4.4.2 (fixed in 4.4.2)

Published 2026-09-04. Last modified 2026-09-08.