A vulnerability, which was classified as problematic, has been found in wplegalpages WPLP Cookie Consent Plugin up to 4.3.7 on WordPress. The impacted element is the function process_bulk_action. This manipulation causes cross-site request forgery.

This vulnerability is tracked as CVE-2026-15136. The attack is possible to be carried out remotely. No exploit exists.