CVE-2026-75865 is a critical unauthenticated arbitrary file upload vulnerability in the WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode WordPress plugin (developed by wplegalpages, published under the gdpr-cookie-consent slug). The flaw allows unauthenticated attackers to upload arbitrary files — including malicious executable content — to a vulnerable site, which can lead to full remote code execution. The issue carries a CVSS v3.1 base score of 9.8 (Critical).
