What is CVE-2026-13389?
CVE-2026-13389 allows unauthenticated attackers to exploit missing authorization checks on REST API routes in the webtoffee-cookie-consent WordPress plugin before version 3.5.3, leading to export, deletion of consent records, post creation, and plugin modification. Users should update the plugin to version 3.5.3 or later to mitigate the risk.
Azərbaycanca: CVE-2026-13389, webtoffee-cookie-consent WordPress plugin-in 3.5.3 versiyasından əvvəlki versiyalarında REST API marşrutlarında avtorizasiya yoxlaması aparılmadığı üçün autentifikasiya olunmamış hücumçulara ziyarətçi razılıq qeydlərini ixrac etmək, silmək, post yaratmaq və plaqin parametrlərini dəyişdirmək imkanı verir. Bu boşluqdan qorunmaq üçün plugin-i ən azı 3.5.3 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the webtoffee-cookie-consent plugin are affected by CVE-2026-13389?
This vulnerability affects all versions of the webtoffee-cookie-consent WordPress plugin before version 3.5.3.
What actions can an unauthenticated attacker perform by exploiting CVE-2026-13389?
Due to missing authorization checks on REST API routes, an attacker can export and delete visitor consent records, create posts, and modify plugin settings.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.