What is CVE-2026-15388?
CVE-2026-15388 is a vulnerability in the Cookie Consent WordPress plugin before version 0.0.10. It fails to properly enforce an administrator-only capability check on consent-settings REST routes, falling back to authentication-only, which allows any authenticated user (e.g., a subscriber) to update plugin settings. Users should update to version 0.0.10 or later to mitigate the issue.
Azərbaycanca: CVE-2026-15388, Cookie Consent WordPress plugin-in 0.0.10 versiyasından əvvəlki versiyalarında aşkarlanmış zəiflikdir. Bu boşluq, admin hüququ tələb etməli olan consent-settings REST route-larda yalnız autentifikasiya tələb edir, imtiyazlı olmayan hər hansı bir abunəçi kimi istifadəçiyə plugin parametrlərini dəyişməyə imkan verir. Plugin-i ən azı 0.0.10 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
Which versions of the Cookie Consent plugin are affected by CVE-2026-15388?
This vulnerability affects all versions of the Cookie Consent WordPress plugin before version 0.0.10.
What can a subscriber do by exploiting CVE-2026-15388?
Any authenticated user, such as a subscriber, can update the plugin settings via the consent-settings REST routes.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.