MEDIUM 5.3 NVD
CVE-2026-17587
The My Agile Privacy® – CMP, Cookie Consent & Privacy Tools plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.3
The My Agile Privacy® – CMP, Cookie Consent & Privacy Tools plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.3.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to modify plugin settings including missing_cookie_shield, cookie_shield_running, cmode_v2_js_on_error, cmode_v2_js_error_code, and cmode_v2_js_error_motivation stored in the plugin's settings key.
References
- https://plugins.trac.wordpress.org/browser/myagileprivacy/tags/3.3.6/frontend/my-agile-pri
- https://plugins.trac.wordpress.org/browser/myagileprivacy/tags/3.3.6/frontend/my-agile-pri
- https://plugins.trac.wordpress.org/browser/myagileprivacy/tags/3.3.6/frontend/my-agile-pri
- https://plugins.trac.wordpress.org/browser/myagileprivacy/tags/3.3.6/includes/my-agile-pri
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3650495%40myagileprivacy&new=36
This medium severity vulnerability with a CVSS score of 5.3 was published on 2026-08-25 via NVD.
vulnfeed aggregates 12116 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.