What is CVE-2026-18046?
CVE-2026-18046 is a vulnerability in the Cookie Consent WordPress plugin (before version 0.0.10) where an intended administrator-only capability check on a REST route storing a geolocation service license key is not enforced, falling back to a simple authentication gate. This allows any authenticated user, like a subscriber, to modify the sensitive license key. Updating to the latest plugin version is recommended.
Azərbaycanca: CVE-2026-18046, Cookie Consent WordPress plaginində (0.0.10-dan əvvəlki versiyalarda) geolokasiya xidməti lisenziya açarını saxlayan REST route üzərində düzgün icazə yoxlamasının edilməməsidir. Bu, hər hansı autentifikasiya olunmuş istifadəçiyə (məsələn, abunəçiyə) həssas məlumatı dəyişdirməyə imkan verir. Plaqinin ən son versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the Cookie Consent plugin are affected by CVE-2026-18046?
This vulnerability affects the Cookie Consent WordPress plugin in versions before 0.0.10. Updating to the latest version resolves the issue.
What level of permission does an attacker need to exploit CVE-2026-18046?
Any authenticated user, such as a subscriber, is sufficient to exploit this because the REST route does not properly enforce the intended administrator-only capability check.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.