top of page
perceptive_background_267k.jpg

Unrestricted Upload of File with Dangerous Type vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent allows Using Malicious Files.…

Published:

31 August 2026 at 00:00:00

Alert date:

31 August 2026 at 18:02:55

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies

A critical Unrestricted Upload of File with Dangerous Type vulnerability has been identified in the WP Cookie Notice for GDPR, CCPA & ePrivacy Consent WordPress plugin by WP Legal Pages. The vulnerability affects all versions up to and including 4.4.1. Exploitation of this flaw allows attackers to upload malicious files to the affected WordPress installation. This type of vulnerability can lead to remote code execution, full site compromise, or deployment of web shells. The issue is tracked as CVE-2026-82970 and has been published by both NVD/NIST and Patchstack. WordPress site administrators using this plugin are advised to update to a patched version immediately. No workaround details are provided beyond patching.

Technical details

Mitigation steps:

Affected products:

WP Cookie Notice for GDPR
CCPA & ePrivacy Consent (up to 4.4.1)

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page