


Perceptive Security
SOC/SIEM Consultancy

Unrestricted Upload of File with Dangerous Type vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent allows Using Malicious Files.…
Published:
31 August 2026 at 00:00:00
Alert date:
31 August 2026 at 18:02:55
Source:
nvd.nist.gov
Web Technologies
A critical Unrestricted Upload of File with Dangerous Type vulnerability has been identified in the WP Cookie Notice for GDPR, CCPA & ePrivacy Consent WordPress plugin by WP Legal Pages. The vulnerability affects all versions up to and including 4.4.1. Exploitation of this flaw allows attackers to upload malicious files to the affected WordPress installation. This type of vulnerability can lead to remote code execution, full site compromise, or deployment of web shells. The issue is tracked as CVE-2026-82970 and has been published by both NVD/NIST and Patchstack. WordPress site administrators using this plugin are advised to update to a patched version immediately. No workaround details are provided beyond patching.
Technical details
Mitigation steps:
Affected products:
WP Cookie Notice for GDPR
CCPA & ePrivacy Consent (up to 4.4.1)
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-82970
https://patchstack.com/database/wordpress/plugin/gdpr-cookie-consent/vulnerability/wordpress-wp-cookie-notice-for-gdpr-ccpa-eprivacy-consent-plugin-4-4-1-arbitrary-file-upload-vulnerability?_s_id=cve
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
