CVE-2026-17587

My Agile Privacy® <= 3.3.6 - Missing Authorization to Unauthenticated Plugin Settings Modification via map_missing_cookie_shield / map_check_consent_mode_status AJAX Actions

The My Agile Privacy® – CMP, Cookie Consent & Privacy Tools plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.3.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to modify plugin settings including missing_cookie_shield, cookie_shield_running, cmode_v2_js_on_error, cmode_v2_js_error_code, and cmode_v2_js_error_motivation stored in the plugin's settings key.


We have discovered 2,579 live websites that are affected by CVE-2026-17587.

Run a Free Instant Scan




Affected Software

Product  Myagileprivacy
Category Wordpress Plugins
Vulnerable Domains2,579 live websites (100% of Myagileprivacy install base)
Vulnerable Versions
  • from 0 through 3.3.6
Vulnerable Versions Count40 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Aug 25, 2026
  • Updated - Aug 25, 2026

Credits

  • Wordfence PRISM (finder)

Website Distribution by Country

Number of websites using CVE-2026-17587
United States142 websites



Italy2,207 websites
Germany85 websites
France60 websites
Spain15 websites
GB15 websites
Switzerland9 websites
Netherlands8 websites
Cyprus6 websites
Belgium5 websites

Website Distribution by TLD

Number of websites using CVE-2026-17587
.it1,643 websites
.com674 websites
.org58 websites
.net57 websites
.eu41 websites
.de22 websites
.info15 websites
.ch8 websites
.co.uk5 websites
.io4 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-17587

Top websites that are affected by CVE-2026-17587. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*************.it Italy***,***
*******.it United States***,***
*****.it Italy***,***
*************.it Italy***,***
*****************.net United States***,***
****.it Italy***,***
********.pl Poland***,***
**********.org United States***,***
***.it United States***,***
***********.com Italy***,***
See full domain list

FAQ

CVE-2026-17587 is Missing Authorization in Myagileprivacy
A total of 2,579 websites have been identified as vulnerable to CVE-2026-17587, based on global website indexing conducted by WebTechSurvey.
The Myagileprivacy is affected by the CVE-2026-17587 vulnerability.
Myagileprivacy versions up to and including 3.3.6 are vulnerable to CVE-2026-17587.