What is CVE-2026-15136?
The WPLP Cookie Consent plugin for WordPress up to version 4.3.7 is vulnerable to Cross-Site Request Forgery (CSRF) due to missing nonce validation in the 'process_bulk_action' function. This allows unauthenticated attackers to perform specific actions. Update the plugin immediately.
Azərbaycanca: WordPress üçün WPLP Cookie Consent pluginində (versiya 4.3.7 və aşağı) Cross-Site Request Forgery (CSRF) zəifliyi aşkar edilib. Bu, 'process_bulk_action' funksiyasında düzgün nonce yoxlamasının olmaması səbəbindən baş verir və autentifikasiya olunmamış hücumçulara xüsusi əməliyyatlar icra etdirməyə imkan verir. Plugin dərhal ən son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-352
FAQ2
Which versions of the WPLP Cookie Consent plugin for WordPress are vulnerable to the CSRF flaw?
Version 4.3.7 and all lower versions are vulnerable to this CSRF flaw.
What is the main cause of the CSRF vulnerability in the WPLP Cookie Consent plugin?
The vulnerability is caused by missing nonce validation in the 'process_bulk_action' function.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.