1 vulnerability across 1 product scored HIGH or above on September 01, 2026.
- ๐ HIGH: 1
Exploit Status Upgrades
The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
- [UPGRADED] CVE-2026-65641 (veeam/one) โ F1: exploitable โ functional, AAS: 10.4 โ 12.4 (HIGH โ CRITICAL). Originally in 2026-08-26 bulletin.
๐ [HIGH] wplegalpages/wplp_cookie_consent_โcookie_banner&_consent_management_for_gdpr,ccpa&_google_consent_mode
1 CVE | CVSS 3.1: 9.8 | AAS 10.1
cpe:2.3:a:wplegalpages:wplp_cookie_consent_cookie_banner_consent_management_for_gdpr_ccpa_google_consent_mode:*:*:*:*:*:*:*:*
WPLegalPages WPLP Cookie Consent Plugin โ Critical Arbitrary File Upload
One critical-severity vulnerability (CVE-2026-75865, CVSS 9.8) affects the WPLP Cookie Consent โ Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode plugin for WordPress in all versions through 4.4.1. The flaw stems from missing file type validation in the saas_upload_logo function combined with an authorization bypass on the WPLP connector REST endpoints, allowing unauthenticated attackers to upload arbitrary files to the server, potentially achieving remote code execution.
Any WordPress site running this plugin should treat this as an immediate priority. Administrators should update to a patched version as soon as one is available, or deactivate the plugin until a fix is confirmed. Review the vendor changeset at the advisory link for patch details, and inspect affected servers for signs of unauthorized file uploads or web shells.
- ๐ CVE-2026-75865 (CVSS 3.1: 9.8)