CVE-2026-14989 | wplegalpages Cookie Banner for GDPR CCPA – WPLP Cookie Consent Plugin consent-logging AJAX endpoint wp_localize_script cross site scripting
A vulnerability, which was classified as problematic, was found in wplegalpages Cookie Banner for GDPR CCPA – WPLP Cookie Consent Plugin up to 4.4.1 on WordPress. This affects the function wp_localize_script of the component consent-logging AJAX endpoint. The manipulation of the argument wpl_user_preference results in cross site scripting.
This vulnerability is cataloged as CVE-2026-14989. The attack may be launched remotely. There is no exploit available.VulDB Recent EntriesRead More