๐Ÿ” CVE Alert

CVE-2026-18046

UNKNOWN 0.0

Cookie Consent < 0.0.10 - Subscriber+ MaxMind License Key Update

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Cookie Consent WordPress plugin before 0.0.10 does not correctly enforce its intended administrator-only capability check on the REST route that stores its geolocation service license key, so the route falls back to an authentication-only gate, allowing any authenticated user such as a subscriber to overwrite the stored key and disrupt the Cookie Consent WordPress plugin before 0.0.10's geolocation-based consent banner targeting.

Vendor unknown
Product cookie consent
Published Aug 12, 2026
Stay Ahead of the Next One

Get instant alerts for unknown cookie consent

Be the first to know when new unknown vulnerabilities affecting unknown cookie consent are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Cookie Consent
0.0.9 < 0.0.10

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/4f5ee68e-3513-4f05-839e-60ae62349f93/

Credits

Erwan LR (WPScan) WPScan