PatchSiren cyber security CVE debrief
CVE-2026-13389 WebToffee CVE debrief
The webtoffee-cookie-consent WordPress plugin before 3.5.3 does not perform authorization checks on several of its REST API routes, allowing unauthenticated attackers to export and delete stored visitor consent records, create posts, and modify the webtoffee-cookie-consent WordPress plugin before 3.5.3's licensing state. This vulnerability affects WordPress installations using the webtoffee-cookie-consent plugin. The plugin's lack of authorization checks on REST API routes could lead to unauthorized access to sensitive data and functionality, potentially allowing attackers to manipulate plugin settings and access sensitive information. Organizations using the webtoffee-cookie-consent WordPress plugin should verify their version and consider updating to version 3.5.3 or later to mitigate potential unauthorized access to sensitive data and functionality. Further verification is required to confirm the extent of the vulnerability and affected systems.
- Vendor
- WebToffee
- Product
- webtoffee-cookie-consent
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-02
- Original CVE updated
- 2026-08-02
- Advisory published
- 2026-08-02
- Advisory updated
- 2026-08-02
Who should care
Administrators of WordPress installations using the webtoffee-cookie-consent plugin should be aware of this vulnerability and take steps to mitigate it. They should verify the version of the plugin, review REST API routes for unauthorized access attempts, and implement additional authentication and authorization checks for sensitive data and functionality. Security teams and vulnerability management teams should also be aware of this vulnerability and review their asset inventory to identify potentially affected systems.
Technical summary
The webtoffee-cookie-consent WordPress plugin before 3.5.3 does not perform authorization checks on several of its REST API routes, allowing unauthenticated attackers to export and delete stored visitor consent records, create posts, and modify the plugin's licensing state. This vulnerability affects WordPress installations using the webtoffee-cookie-consent plugin. The plugin's lack of authorization checks on REST API routes could lead to unauthorized access to sensitive data and functionality.
Defensive priority
Organizations using the webtoffee-cookie-consent WordPress plugin should verify their version and consider updating to version 3.5.3 or later to mitigate potential unauthorized access to sensitive data and functionality.
Recommended defensive actions
- Verify the version of the webtoffee-cookie-consent WordPress plugin and update to version 3.5.3 or later if necessary.
- Monitor REST API routes for unauthorized access attempts.
- Implement additional authentication and authorization checks for sensitive data and functionality.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The evidence for this vulnerability is limited. Further verification is required to confirm the extent of the vulnerability and affected systems. The webtoffee-cookie-consent WordPress plugin before 3.5.3 does not perform authorization checks on several of its REST API routes, allowing unauthenticated attackers to export and delete stored visitor consent records, create posts, and modify the plugin's licensing state. Defenders should verify the version of the plugin, review REST API routes for unauthorized access attempts, and implement additional authentication and authorization checks for sensitive data and functionality.
Official resources
-
CVE-2026-13389 CVE record
CVE.org
-
CVE-2026-13389 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-02T06:16:34.550Z and has not been modified since then.