Skip to main content
QUIETLYTIC
Vulnerability

WP Cookie Notice Vulnerability (CVE-2026-82970)

CVE-2026-82970 is a CVSS 10.0 unrestricted file upload flaw in the WP Cookie Notice WordPress plugin through 4.4.1, reported as exploited by VulnCheck KEV.

CVE-2026-82970
Threat Level
CRITICAL
CVSS
10.0
Status
Active Exploitation
Confidence
Medium
Affected Products
WP Cookie Notice, WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent (through 4.4.1)

CVE-2026-82970 is a CVSS 10.0 unrestricted-file-upload vulnerability in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent, a WordPress consent-banner plugin published by WP Legal Pages. NVD classifies it as CWE-434 (Unrestricted Upload of File with Dangerous Type) and records that the issue affects releases up to and including 4.4.1. VulnCheck’s KEV feed reports the CVE as exploited, dated August 31, 2026.

As with the other maximum-severity plugin CVEs in this batch, the exploitation report is single-sourced. CISA has not added CVE-2026-82970 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion on September 16, 2026, so no Binding Operational Directive 26-04 remediation obligation attaches. VulnCheck’s catalog is broader than CISA’s by design; a listing there reports exploitation without carrying CISA’s federal mandate.

What the flaw is

CWE-434 covers the case where an application accepts an uploaded file without adequately constraining what kind of file it is. On a PHP application the failure mode that matters is a file the web server will subsequently execute rather than serve — which converts an upload feature into an arbitrary-code path without needing any memory-corruption or injection primitive. NVD’s description states the vulnerability allows the use of malicious files; it does not enumerate which validation control is missing, and no second ingested source fills that in.

There is a specific irony worth naming, because it affects how organisations should prioritise this. A consent-banner plugin exists to satisfy GDPR, CCPA, and ePrivacy obligations, and it is installed precisely by operators who are trying to be compliant. A site-level compromise originating in that plugin puts the personal data the plugin was installed to protect at risk, and a personal-data breach arising from an unpatched known vulnerability is squarely the kind of event that triggers notification duties under the same regimes. The compliance tool becomes the compliance incident. That is a reason to move this up a patch queue rather than down it.

Why the score is 10.0

The vector is AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H — identical to the other two plugin CVEs in this batch. Network reachable, low attack complexity, no privileges, no user interaction, and scope changed. The scope metric is what separates 10.0 from 9.8: the assessment is that impact escapes the vulnerable component into the wider security authority, which for a plugin executing inside the host site’s PHP process is a reasonable reading.

Score and vector trace to NVD alone. Our provenance carries no corroborating second source and no conflict.

Evidence and confidence

  • Medium confidence — the CVSS 10.0 score, the vector, the CWE-434 classification, and the affected ceiling of 4.4.1, all sourced to NVD alone; and the exploitation report, sourced to VulnCheck KEV alone.
  • Unknown — exploitation probability. No EPSS score has been ingested for this CVE.
  • Not established — the fixed release. NVD names what is affected, not what remediates it.

One data-quality note, disclosed because it is the kind of thing that should not be quietly smoothed over: VulnCheck’s own title field for this record arrives as a bare weakness label with no vendor or product name attached, unlike its entries for the other CVEs in this batch. That affects nothing factual — the vendor and product are populated correctly in their own fields — but it is why this article leans on NVD’s description for identification.

Why this matters

Consent banners are near-universal on sites serving EU or California visitors, and they are typically installed once and then forgotten, because they are infrastructure rather than a feature anyone actively uses. That combination — broad deployment, low attention — is what makes a maximum-severity flaw in this category worth more than its install count alone would suggest. Nobody audits their cookie notice.

On the exploitation question, the honest position is the same one we take on the rest of this batch: patch on the severity, which is well established, rather than on the exploitation report, which is not corroborated. An unauthenticated file-upload path to code execution on a widely-installed plugin justifies prompt action whether or not it is currently being exploited, and that reasoning does not depend on resolving the single-source question.

This is one of three WordPress plugin CVEs scored 10.0 that entered VulnCheck’s KEV feed between August 18 and August 31, 2026 without a corresponding CISA listing. It shares its August 31 VulnCheck date with CVE-2026-82222 in GiveWP; CVE-2026-73343 in WP Compress completes the set. The three share an identical CVSS vector and no shared code — the common factor is that WordPress plugins run with the site’s full privileges, so any of them reaching code execution produces the same scope assessment. For a lower-severity example of the same ecosystem risk, see CVE-2026-2390 in PowerKit.

Frequently Asked Questions

What is CVE-2026-82970? A CVSS 10.0 unrestricted-file-upload vulnerability (CWE-434) in the WP Cookie Notice for GDPR, CCPA & ePrivacy Consent WordPress plugin by WP Legal Pages, affecting releases through 4.4.1.

Is CVE-2026-82970 being actively exploited? VulnCheck’s KEV feed reports it as exploited, dated August 31, 2026. That report is single-sourced; CISA has not listed this CVE as of our September 16, 2026 ingestion, and we have no independent corroboration. Treat it as reported exploitation, not confirmed.

Which version fixes it? NVD names releases through 4.4.1 as affected but states no fixed version, and our ingested data carries none. Confirm the remediated release against WP Legal Pages’ own advisory or the Patchstack database entry linked from NVD.

Does this CVE create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.

Is deactivating the plugin an adequate interim step? Our source data names no vendor workaround, and we will not invent one. Note that deactivating a consent-banner plugin has its own compliance consequences for sites serving EU or California visitors, so removal is not a cost-free mitigation — weigh it against upgrading promptly instead.

Does a GDPR plugin vulnerability itself constitute a breach? No. An unpatched vulnerability is not a breach, but a compromise arising from one that exposes personal data may trigger notification duties under GDPR, CCPA, or ePrivacy. That is a question for your own counsel against your own facts, not something this advisory can determine.


Severity, vector, weakness classification, affected-version ceiling, and description sourced from the National Vulnerability Database record for CVE-2026-82970. Exploitation status and the August 31, 2026 catalog date are reported by VulnCheck KEV, an authenticated feed with no public per-CVE page to cite. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our ingestion through September 16, 2026. Advisory reference linked from NVD: Patchstack database entry. Aggregated September 17, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 VulnCheck KEV

Related intelligence


Analyst tools