← לוח פגיעויות

CVE-2026-82184

בינונית 5.3

תיאור (מקור, אנגלית)

The WPLP Cookie Consent WordPress plugin before 4.4.2 does not have any authorisation or CSRF checks when storing visitor consent state, and the code that does so runs on every front-end page load, allowing unauthenticated attackers to overwrite a site-wide option with arbitrary data.

מדדים

CVSS 3.1
5.3 (MEDIUM) מקור הציון: CNA CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS — סבירות ניצול
0% (אחוזון 000) נכון ל-5/10/2026
CWE
CWE-862

קישורים