CVE-2026-12955: CWE-862 Missing Authorization in wplegalpages Cookie Banner for GDPR / CCPA – WPLP Cookie Consent
The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the gdpr_cookie_consent_ajax_save_schedule_scan() function (the wp_ajax_gcc_save_schedule_scan AJAX action) in versions up to, and including, 4.3.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify the plugin's cookie scan schedule configuration stored in the gdpr_scan_schedule_data option, which is an administrative function intended to be limited to users with the manage_options capability.
AI Analysis
Technical Summary
CVE-2026-12955 describes a missing authorization vulnerability in the GDPR Cookie Consent plugin for WordPress (WPLP Cookie Consent) versions up to and including 4.3.6. The vulnerability exists in the gdpr_cookie_consent_ajax_save_schedule_scan() function, which handles the wp_ajax_gcc_save_schedule_scan AJAX action. Due to the absence of capability checks and nonce verification, authenticated users with low privileges (Subscriber-level and above) can modify the gdpr_scan_schedule_data option, an administrative setting intended to be managed only by users with the manage_options capability. This unauthorized modification could affect the plugin's cookie scan scheduling.
Potential Impact
The vulnerability allows authenticated users with Subscriber-level access or higher to modify administrative configuration data related to the cookie scan schedule. While it does not disclose sensitive information or allow privilege escalation directly, it permits unauthorized changes to plugin settings, potentially disrupting cookie compliance operations.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict user roles to trusted users only and monitor for unauthorized changes to the gdpr_scan_schedule_data option. Applying principle of least privilege to user roles may reduce risk.
CVE-2026-12955: CWE-862 Missing Authorization in wplegalpages Cookie Banner for GDPR / CCPA – WPLP Cookie Consent
Description
The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the gdpr_cookie_consent_ajax_save_schedule_scan() function (the wp_ajax_gcc_save_schedule_scan AJAX action) in versions up to, and including, 4.3.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify the plugin's cookie scan schedule configuration stored in the gdpr_scan_schedule_data option, which is an administrative function intended to be limited to users with the manage_options capability.
CVSS v3.1
Score 4.3medium
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-12955 describes a missing authorization vulnerability in the GDPR Cookie Consent plugin for WordPress (WPLP Cookie Consent) versions up to and including 4.3.6. The vulnerability exists in the gdpr_cookie_consent_ajax_save_schedule_scan() function, which handles the wp_ajax_gcc_save_schedule_scan AJAX action. Due to the absence of capability checks and nonce verification, authenticated users with low privileges (Subscriber-level and above) can modify the gdpr_scan_schedule_data option, an administrative setting intended to be managed only by users with the manage_options capability. This unauthorized modification could affect the plugin's cookie scan scheduling.
Potential Impact
The vulnerability allows authenticated users with Subscriber-level access or higher to modify administrative configuration data related to the cookie scan schedule. While it does not disclose sensitive information or allow privilege escalation directly, it permits unauthorized changes to plugin settings, potentially disrupting cookie compliance operations.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict user roles to trusted users only and monitor for unauthorized changes to the gdpr_scan_schedule_data option. Applying principle of least privilege to user roles may reduce risk.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Wordfence
- Date Reserved
- 2026-06-22T21:19:30.826Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a50b54868715ace4351b358
Added to database: 07/10/2026, 09:03:04 UTC
Last enriched: 07/17/2026, 09:45:40 UTC
Last updated: 08/24/2026, 22:52:08 UTC
Views: 58
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.