What is CVE-2026-13360?
CVE-2026-13360 is a Stored Cross-Site Scripting (XSS) vulnerability in the WPLP Cookie Consent plugin for WordPress up to version 4.3.5. The flaw via the 'regionArray' parameter allows unauthenticated attackers to inject malicious scripts due to insufficient input sanitization. Users should update the plugin to the latest version immediately.
Azərbaycanca: CVE-2026-13360 WordPress üçün WPLP Cookie Consent plugin-inin 4.3.5 və əvvəlki versiyalarında aşkarlanan Stored XSS zəifliyidir. 'regionArray' parametri vasitəsilə autentifikasiya olunmamış hücumçuya zərərli skript yerləşdirməyə imkan verir. Plugin-i dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which plugin is affected by CVE-2026-13360, and what is the latest vulnerable version?
This vulnerability affects the WPLP Cookie Consent plugin for WordPress, version 4.3.5 and earlier.
How can an attacker exploit CVE-2026-13360 to inject a script?
An attacker can inject a malicious script via the 'regionArray' parameter due to insufficient input sanitization in the plugin.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.