PatchSiren

wplegalpages CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH wplegalpages CVE published 2026-08-15

CVE-2026-13360

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-15T04:18:01.957Z and has not been modified since then. The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'regionArray' parameter in all versions up to, and including, 4.3.5 due to insufficient input sanitization and outp [truncated]

MEDIUM wplegalpages CVE published 2026-07-10

CVE-2026-14475

The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to generic SQL Injection via the 'scan_id' parameter in all versions up to, and including, 4.3.6. This vulnerability allows authenticated attackers, with administrator-level access and above, to append additional SQL queries into existing queries, potentially leading to sensitive information extraction from the database.

MEDIUM wplegalpages CVE published 2026-07-10

CVE-2026-12955

The GDPR Cookie Consent plugin for WordPress has a vulnerability allowing unauthorized modification of data due to a missing capability check and nonce verification on the gdpr_cookie_consent_ajax_save_schedule_scan() function. Authenticated attackers with Subscriber-level access can modify the plugin's cookie scan schedule configuration. This vulnerability affects versions up to and including 4.3.6 of th [truncated]