A vulnerability, which was classified as problematic, has been found in wplegalpages WPLP Cookie Consent Plugin up to 4.3.7 on WordPress. The impacted element is the function
process_bulk_action. This manipulation causes cross-site request forgery.
This vulnerability is tracked as CVE-2026-15136. The attack is possible to be carried out remotely. No exploit exists.