Catapultthemes
Catapultthemes Cookie Consent: vulnerabilidades y CVE
Catapultthemes Cookie Consent tiene 7 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses6
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-85131 | Media (6.5) | 0.20% | — | 16 sept 2026 | The WPLP Cookie Consent WordPress plugin before 4.4.4 does not perform CSRF or capability checks when processing bulk actions on its administration screens, and does not restrict the targeted items to its own records,… |
| CVE-2026-85133 | Media (5.4) | 0.23% | — | 9 sept 2026 | The WPLP Cookie Consent WordPress plugin before 4.4.2 does not perform nonce or capability checks on several of its settings AJAX actions, allowing any authenticated user, such as a subscriber, to read and destroy scan… |
| CVE-2026-82185 | Media (4.3) | 0.25% | — | 9 sept 2026 | The WPLP Cookie Consent WordPress plugin before 4.4.2 does not have capability or nonce checks on some of its A/B testing actions, allowing any authenticated user, such as a subscriber, to overwrite the cookie banner… |
| CVE-2026-82184 | Media (5.3) | 0.16% | — | 9 sept 2026 | The WPLP Cookie Consent WordPress plugin before 4.4.2 does not have any authorisation or CSRF checks when storing visitor consent state, and the code that does so runs on every front-end page load, allowing… |
| CVE-2026-18046 | Media (4.3) | 0.31% | — | 12 ago 2026 | The Cookie Consent WordPress plugin before 0.0.10 does not correctly enforce its intended administrator-only capability check on the REST route that stores its geolocation service license key, so the route falls back to… |
| CVE-2026-15388 | Media (4.3) | 0.33% | — | 12 ago 2026 | The Cookie Consent WordPress plugin before 0.0.10 does not correctly enforce its intended administrator-only capability check on its consent-settings REST routes, so they fall back to an authentication-only gate,… |
| CVE-2018-10310 | Media (5.4) | 3.8% | — | 25 abr 2018 | A persistent cross-site scripting vulnerability has been identified in the web interface of the Catapult UK Cookie Consent plugin before 2.3.10 for WordPress that allows the execution of arbitrary HTML/script code in… |