CVE-2026-75865 is an unrestricted file upload vulnerability in WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode for WordPress through version 4.4.1. The saas_upload_logo() function does not enforce file-type validation, and an authorization bypass in WPLP connector REST endpoints permits unauthenticated access to the upload functionality. An unauthenticated remote attacker can upload arbitrary, potentially server-executable content to an affected site's server.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This five-file repository contains a Python 3 exploitation tool, a minimal PHP proof payload, and supporting README/report documentation for CVE-2026-75865. The target is the WordPress gdpr-cookie-consent plugin through version 4.4.1. The PoC is an operational multithreaded scanner and exploit runner: it reads a URL list, fingerprints the plugin via readme files or the upload route, uses a SaaS-issued JWT, abuses /store-auth to set a random known master key, and sends base64-encoded payload data with an attacker-selected filename to /upload-logo. It tries PHP-related extensions, verifies each uploaded URL, and logs successful URLs immediately. It can additionally upload an .htaccess file intended to restrict directory access while explicitly re-allowing the uploaded payload, potentially bypassing or counteracting parent access behavior. The bundled payload is non-interactive and only emits a marker or self-deletes, but --shell permits replacement with arbitrary PHP, making the underlying impact remote code execution. No named exploit framework is used.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Critical unauthenticated arbitrary PHP file-upload and remote-code-execution vulnerability in the WPLP Cookie Consent WordPress plugin. It affects versions 4.4.1 and earlier, caused by missing file-type validation in saaS_upload_logo() combined with an authorization bypass in WPLP connector REST endpoints.
An unauthenticated arbitrary-file-upload vulnerability in the WPLP Cookie Consent WordPress plugin. Missing file-type validation in saas_upload_logo(), combined with authorization bypasses affecting WPLP connector REST endpoints, allows uploads of arbitrary files to the affected server and may enable remote code execution.
An unauthenticated arbitrary-file-upload vulnerability in the WPLP Cookie Consent WordPress plugin, caused by missing file-type validation and an authorization bypass in WPLP connector REST endpoints. It may enable remote code execution by allowing arbitrary files to be uploaded to the affected server.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.