CVE-2026-12920: SQL Injection in WPLP Cookie Consent WordPress Plugin
The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent WordPress plugin contains a SQL injection vulnerability in versions 4.3.5 and earlier. An authenticated administrator can craft malicious input through the 's' parameter to inject arbitrary SQL commands and extract sensitive data from the WordPress database. While the vulnerability requires admin-level access to exploit, it poses a meaningful risk in multi-user WordPress environments or where admin credentials have been compromised.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 4.9 MEDIUM · CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- Weaknesses (CWE)
- CWE-89
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-07-03 / 2026-07-06
NVD description (verbatim)
The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, and including, 4.3.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
6 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-12920 is a SQL injection flaw (CWE-89) in the WPLP Cookie Consent plugin affecting all versions through 4.3.5. The vulnerability exists in the handling of the 's' parameter, where user-supplied input is neither properly escaped nor parameterized before being incorporated into SQL queries. An attacker with administrator privileges can append additional SQL statements to existing queries, enabling unauthorized data exfiltration from the database. The CVSS v3.1 score of 4.9 (MEDIUM) reflects the high confidentiality impact, though exploitation is limited to authenticated high-privilege users.
Business impact
In WordPress installations with the WPLP Cookie Consent plugin, a compromised administrator account—or a legitimate admin with malicious intent—can extract sensitive data including user records, customer information, and site configuration details. This could lead to privacy violations, regulatory exposure (particularly under GDPR and CCPA), and reputational damage. Affected organizations should prioritize identifying plugin installations and verifying administrator account integrity.
Affected systems
The vulnerability affects WordPress sites using the Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin in any version up to and including 4.3.5. No information on newer versions or patch availability is provided in the advisory; verify the current plugin version and consult the vendor for update status.
Exploitability
Exploitation requires authenticated access with administrator-level privileges, significantly limiting the attack surface. However, the barrier is not insurmountable: compromised admin accounts, insider threats, or supply-chain compromises of plugin developers could enable attacks. The network-accessible nature of the vulnerability (AV:N) means no additional network prerequisites are needed once credentials are obtained. Detection and prevention depend on robust access controls and credential hygiene.
Remediation
Organizations should immediately verify which WordPress installations use the WPLP Cookie Consent plugin and identify the installed version. Upgrade to a patched version if available from the plugin vendor—consult the official plugin repository or vendor advisory for version 4.3.6 or later. Until patching is possible, restrict administrator account access to trusted users, enforce strong password policies, enable multi-factor authentication, and monitor database query logs for suspicious SQL activity.
Patch guidance
Check the official WordPress plugin repository and the plugin vendor's advisory for available updates beyond version 4.3.5. Apply patches at your earliest maintenance window, prioritizing production sites with sensitive customer data. Verify the patched version has been tested in a staging environment before production deployment. If no vendor patch is available within a defined timeframe, evaluate alternative GDPR/CCPA compliance plugins with better security practices.
Detection guidance
Monitor WordPress administrator activity, particularly any use of the cookie consent plugin's settings or filtering functionality. Log and alert on unusual database queries, especially those containing UNION, SELECT, or other SQL commands appended to expected queries. Review WordPress audit logs for admin account access from unusual locations or times. Consider implementing a Web Application Firewall (WAF) rule set to detect SQL injection patterns in HTTP parameters, though this is a secondary control to patching.
Why prioritize this
While the CVSS score is MEDIUM and exploitation requires high-privilege access, this vulnerability affects a security and compliance plugin trusted to handle sensitive user consent data. The combination of direct database access potential and the plugin's role in GDPR/CCPA compliance makes this a priority for timely remediation, particularly in organizations subject to privacy regulations.
Risk score, explained
The CVSS v3.1 score of 4.9 reflects high confidentiality impact (C:H) but limited access requirements (PR:H—high privilege required). The score appropriately penalizes the privilege requirement while acknowledging the serious data exposure risk. Organizations handling sensitive data should treat this as higher priority than the score alone suggests, as insider threats and credential compromise are realistic scenarios.
Frequently asked questions
Do I need to update immediately?
If your WordPress installation runs WPLP Cookie Consent version 4.3.5 or earlier, plan an update as soon as a patched version is available from the vendor. In the interim, ensure only trusted administrators have access and monitor admin activity closely. If you have no multi-user WordPress setup, the immediate risk is lower but patching should not be deferred.
Can non-administrators exploit this?
No. The vulnerability explicitly requires administrator-level access or higher to exploit. This significantly limits attack surface in typical WordPress environments, but compromised admin accounts, disgruntled employees, or plugin developers with malicious intent remain realistic threat scenarios.
Will a WAF protect me if I cannot patch immediately?
A WAF can provide temporary mitigation by detecting SQL injection patterns in the 's' parameter, but it is not a substitute for patching. WAF rules may be bypassed with sophisticated encoding techniques. Focus on patching as the primary remediation; WAF is a secondary control.
What if the vendor hasn't released a patch yet?
Contact the plugin vendor directly and request an update timeline. In the interim, restrict administrator access to essential personnel, enable two-factor authentication, and monitor database logs. If no patch is forthcoming, consider migrating to an alternative GDPR/CCPA compliance plugin.
This analysis is based on the vulnerability advisory published on 2026-07-03 and modified on 2026-07-06. No exploit code is provided or recommended. Patch versions and availability should be verified directly with the plugin vendor before deployment. Readers are responsible for assessing risk within their own environment and applying appropriate controls. SEC.co does not guarantee the completeness or accuracy of information derived from third-party sources. Source: NVD (public-domain), retrieved 2026-08-11. Analysis generated by SEC.co (claude-haiku-4-5).
Weaknesses (CWE)
Related vulnerabilities
- CVE-2025-53648MEDIUMSQL Misconfiguration in Apache Gravitino UI – MEDIUM Severity
- CVE-2025-71332MEDIUMSQL Injection in Flowise importChatflows API – MEDIUM Severity Credential Extraction
- CVE-2026-0075MEDIUMAndroid SQL Injection in Contacts Database – Privilege Escalation Risk
- CVE-2026-10039MEDIUMFrontend Admin WordPress Plugin SQL Injection Vulnerability
- CVE-2026-10155MEDIUMSQL Injection in Bdtask Multi-Store Inventory Management System 1.0
- CVE-2026-10170MEDIUMSQL Injection in code-projects Visitor Management System 1.0
- CVE-2026-10171MEDIUMSQL Injection in code-projects Online Music Site 1.0 AdminUpdateAlbum.php
- CVE-2026-10176MEDIUMSQL Injection in Aider-AI Aider 0.86.3 Code Generation