๐Ÿ” CVE Alert

CVE-2026-15388

UNKNOWN 0.0

Cookie Consent < 0.0.10 - Subscriber+ Consent Settings Update and Consent Log Disclosure

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Cookie Consent WordPress plugin before 0.0.10 does not correctly enforce its intended administrator-only capability check on its consent-settings REST routes, so they fall back to an authentication-only gate, allowing any authenticated user such as a subscriber to update the Cookie Consent WordPress plugin before 0.0.10's consent settings and, on sites connected to the vendor's paid plan, read stored visitor consent logs.

Vendor unknown
Product cookie consent
Published Aug 12, 2026
Stay Ahead of the Next One

Get instant alerts for unknown cookie consent

Be the first to know when new unknown vulnerabilities affecting unknown cookie consent are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Cookie Consent
0 < 0.0.10

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/e322dfb6-66b3-4deb-98ba-a19707e5a7e1/

Credits

Shivamani Vastrala WPScan