
CVE-2026-13389 The webtoffee-cookie-consent WordPress plugin before 3.5.3 does not perform authorization checks on several of its REST API routes, allowing unauthenticated attackers… https://www.cve.org/CVERecord?id=CVE-2026-13389
Post summary
The text announces a vulnerability in the webtoffee-cookie-consent WordPress plugin that allows unauthenticated attackers to exploit missing authorization checks on its REST API routes.


