
CVE-2026-18046 The Cookie Consent WordPress plugin before 0.0.10 does not correctly enforce its intended administrator-only capability check on the REST route that stores its geolo… https://www.cve.org/CVERecord?id=CVE-2026-18046
Post summary
The CVE‑2026‑18046 disclosure highlights a privilege‑bypass issue in the Cookie Consent WordPress plugin caused by an unchecked REST endpoint.

