Complianz – GDPR/CCPA Cookie Consent <= 7.5.1 - Authenticated (Administrator+) PHP Object Injection
medium
The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 7.5.1 via deserialization of untrusted input. This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP Object. No known POP chain is...
- CVSS:
- 6.6
- Affected:
- up to 7.5.1
- Fixed in:
- 7.5.2
- Disclosed:
- Jul 22, 2026
CVE-2026-65497 on NVD →
Complianz – GDPR/CCPA Cookie Consent <= 7.5.1 - Authenticated (Author+) Server-Side Request Forgery
medium
The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.5.1. This makes it possible for authenticated attackers, with Author-level access and above, to make web requests to arbitrary locations originating from the web application...
- CVSS:
- 6.4
- Affected:
- up to 7.5.1
- Fixed in:
- 7.5.2
- Disclosed:
- Jul 22, 2026
CVE-2026-65496 on NVD →
Complianz – GDPR/CCPA Cookie Consent <= 7.5.1 - Unauthenticated Information Exposure
medium
The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.5.1. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 7.5.1
- Fixed in:
- 7.5.2
- Disclosed:
- Jul 22, 2026
CVE-2026-65498 on NVD →
Complianz – GDPR/CCPA Cookie Consent <= 7.4.5 - Missing Authorization to Unauthenticated Private Post Content Disclosure via Consent Area REST Endpoint
medium
The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to unauthorized data access in all versions up to, and including, 7.4.5 This is due to the REST API endpoint at /wp-json/complianz/v1/consent-area/{post_id}/{block_id} using __return_true as the permission_callback, allowing any unauthenticated...
- CVSS:
- 5.3
- Affected:
- up to 7.4.5
- Fixed in:
- 7.4.6
- Disclosed:
- Apr 28, 2026
CVE-2026-4019 on NVD →
Complianz - WordPress Complianz - GDPR/CCPA Cookie Consent plugin <= 7.4.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Content Filter vulnerability
medium
WordPress Complianz - GDPR/CCPA Cookie Consent plugin <= 7.4.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Content Filter vulnerability
- CVSS:
- 6.5
- Affected:
- up to 7.4.4.2
- Fixed in:
- 7.4.5
- Disclosed:
- Mar 30, 2026
Complianz – GDPR/CCPA Cookie Consent <= 7.4.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Content Filter
medium
The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 7.4.4.2. This is due to the `revert_divs_to_summary` function replacing `”` HTML entities with literal double-quote characters (`"`) in post content without subsequent s...
- CVSS:
- 4.9
- Affected:
- up to 7.4.4.2
- Fixed in:
- 7.4.5
- Disclosed:
- Mar 25, 2026
CVE-2026-2389 on NVD →
Complianz – GDPR/CCPA Cookie Consent [complianz-gdpr] < 7.4.4
unknown
[en] The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cmplz-accept-link shortcode in all versions up to, and including, 7.4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for auth...
- Affected:
- up to 7.4.4
- Fixed in:
- 7.4.4
- Disclosed:
- Feb 18, 2026
CVE-2025-11185 on NVD →
Complianz | GDPR/CCPA Cookie Consent <= 7.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cmplz-accept-link shortcode in all versions up to, and including, 7.4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentic...
- CVSS:
- 6.4
- Affected:
- up to 7.4.3
- Fixed in:
- 7.4.4
- Disclosed:
- Feb 17, 2026
CVE-2025-11185 on NVD →
Complianz – GDPR/CCPA Cookie Consent [complianz-gdpr] < 7.0.0
unknown
[en] The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.5.6. This is due to missing or incorrect nonce validation on the process_delete function in class-DNSMPD.php. This makes it possible for unauthenticated attackers to del...
- Affected:
- up to 7.0.0
- Fixed in:
- 7.0.0
- Disclosed:
- Mar 2, 2024
CVE-2024-1592 on NVD →
Complianz – GDPR/CCPA Cookie Consent <= 6.5.6 - Cross-Site Request Forgery to Data Request Deletion
medium
The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.5.6. This is due to missing or incorrect nonce validation on the process_delete function in class-DNSMPD.php. This makes it possible for unauthenticated attackers to delete G...
- CVSS:
- 4.3
- Affected:
- up to 6.5.6
- Fixed in:
- 7.0.0
- Disclosed:
- Mar 1, 2024
CVE-2024-1592 on NVD →
Complianz – GDPR/CCPA Cookie Consent [complianz-gdpr] < 6.5.6
unknown
[en] The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to and including 6.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permission...
- Affected:
- up to 6.5.6
- Fixed in:
- 6.5.6
- Disclosed:
- Jan 4, 2024
CVE-2023-6498 on NVD →
Complianz | GDPR/CCPA Cookie Consent <= 6.5.5 - Authenticated(Administrator+) Stored Cross-site Scripting via settings
medium
The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to and including 6.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and...
- CVSS:
- 4.4
- Affected:
- up to 6.5.5
- Fixed in:
- 6.5.6
- Disclosed:
- Jan 3, 2024
CVE-2023-6498 on NVD →
Complianz – GDPR/CCPA Cookie Consent [complianz-gdpr] < 6.4.5
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Really Simple Plugins Complianz, Really Simple Plugins Complianz Premium allows Cross-Site Scripting (XSS).This issue affects Complianz: from n/a through 6.4.4; Complianz Premium: from n/a through 6.4.6.1.
- Affected:
- up to 6.4.5
- Fixed in:
- 6.4.5
- Disclosed:
- Nov 30, 2023
CVE-2023-33333 on NVD →
Complianz <= 6.4.4 (Premium <= 6.4.6.1) - Cross-Site Request Forgery to Stored Cross-Site Scripting
medium
The Complianz plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting in versions up to, and including, 6.4.4 (Free) and 6.4.6.1 (Premium). This is due to missing nonce validation on the ajax_script_add() and ajax_script_save() functions called via AJAX actions. This makes it pos...
- CVSS:
- 6.1
- Affected:
- up to 6.4.4
- Fixed in:
- 6.4.5
- Disclosed:
- Jun 21, 2023
CVE-2023-33333 on NVD →
Complianz <= 6.4.5 (Premium <= 6.4.7) - Cross-Site Request Forgery
medium
The Complianz plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting in versions up to, and including, 6.4.5 (Free) and 6.4.7 (Premium). This is due to missing nonce validation on several functions called via AJAX actions such as cmplz_delete_cookiebanner(), cmplz_duplicate_cook...
- CVSS:
- 4.3
- Affected:
- up to 6.4.5
- Fixed in:
- 6.4.6
- Disclosed:
- Jun 20, 2023
CVE-2023-34030 on NVD →
Complianz | GDPR/CCPA Cookie Consent <= 6.4.5 - Cross-Site Request Forgery
medium
The Complianz | GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.4.5. This is due to missing nonce validation on the process_ajax_destination_clear, dismiss_review_notice_callback, and dismiss_warning functions. This makes it possible for unau...
- CVSS:
- 4.3
- Affected:
- up to 6.4.6
- Fixed in:
- 6.4.6
- Disclosed:
- May 30, 2023
CVE-2023-34030 on NVD →
Complianz - GDPR/CCPA Cookie Consent <= 6.4.4 - Cross-Site Request Forgery via ajax_script_save
medium
The Complianz - GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.4.4. This is due to missing or incorrect nonce validation on the ajax_script_save function. This makes it possible for unauthenticated attackers to save scripts via a forged requ...
- CVSS:
- 6.1
- Affected:
- up to 6.4.4
- Fixed in:
- 6.4.5
- Disclosed:
- May 12, 2023
CVE-2023-33333 on NVD →
Complianz - GDPR/CCPA Cookie Consent <= 6.4.4 - Cross-Site Request Forgery via ajax_script_add
medium
The Complianz - GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.4.4. This is due to missing or incorrect nonce validation on the ajax_script_add function. This makes it possible for unauthenticated attackers to add scripts via a forged reques...
- CVSS:
- 6.1
- Affected:
- up to 6.4.4
- Fixed in:
- 6.4.5
- Disclosed:
- May 12, 2023
CVE-2023-33333 on NVD →
Complianz - GDPR/CCPA Cookie Consent <= 6.4.4 - Cross-Site Request Forgery via ajax_delete_snapshot
medium
The Complianz - GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.4.4. This is due to missing or incorrect nonce validation on the ajax_delete_snapshot function. This makes it possible for unauthenticated attackers to delete arbitrary files in...
- CVSS:
- 5.4
- Affected:
- up to 6.4.4
- Fixed in:
- 6.4.5
- Disclosed:
- May 12, 2023
CVE-2023-33333 on NVD →
Complianz - GDPR/CCPA Cookie Consent <= 6.4.4 - Cross-Site Request Forgery via cmplz_delete_cookiebanner
medium
The Complianz - GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.4.4. This is due to missing or incorrect nonce validation on the cmplz_delete_cookiebanner function. This makes it possible for unauthenticated attackers to delete the compliance...
- CVSS:
- 4.3
- Affected:
- up to 6.4.4
- Fixed in:
- 6.4.5
- Disclosed:
- May 12, 2023
Complianz - GDPR/CCPA Cookie Consent <= 6.4.4 - Cross-Site Request Forgery via cmplz_duplicate_cookiebanner
medium
The Complianz - GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.4.4. This is due to missing or incorrect nonce validation on the cmplz_duplicate_cookiebanner function. This makes it possible for unauthenticated attackers to duplicate the comp...
- CVSS:
- 4.3
- Affected:
- up to 6.4.4
- Fixed in:
- 6.4.5
- Disclosed:
- May 12, 2023
Complianz - GDPR/CCPA Cookie Consent <= 6.4.4 - Cross-Site Request Forgery via run_sync
medium
The Complianz - GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.4.4. This is due to missing or incorrect nonce validation on the run_sync function. This makes it possible for unauthenticated attackers to sync cookies and serivces via a forged...
- CVSS:
- 4.3
- Affected:
- up to 6.4.4
- Fixed in:
- 6.4.5
- Disclosed:
- May 12, 2023
CVE-2023-33333 on NVD →
Complianz - GDPR/CCPA Cookie Consent <= 6.4.4 - Cross-Site Request Forgery via ajax_edit_item
medium
The Complianz - GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.4.4. This is due to missing or incorrect nonce validation on the ajax_edit_item function. This makes it possible for unauthenticated attackers to edit items via a forged request...
- CVSS:
- 4.3
- Affected:
- up to 6.4.4
- Fixed in:
- 6.4.5
- Disclosed:
- May 12, 2023
CVE-2023-33333 on NVD →
Complianz - GDPR/CCPA Cookie Consent <= 6.4.4 - Cross-Site Request Forgery via ajax_create_pages
medium
The Complianz - GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.4.4. This is due to missing or incorrect nonce validation on the ajax_create_pages function. This makes it possible for unauthenticated attackers to create pages via a forged req...
- CVSS:
- 4.3
- Affected:
- up to 6.4.4
- Fixed in:
- 6.4.5
- Disclosed:
- May 12, 2023
CVE-2023-33333 on NVD →
Complianz - GDPR/CCPA Cookie Consent <= 6.4.4 - Cross-Site Request Forgery via maybe_install_suggested_plugins
medium
The Complianz - GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.4.4. This is due to missing or incorrect nonce validation on the maybe_install_suggested_plugins function. This makes it possible for unauthenticated attackers to install suggest...
- CVSS:
- 4.3
- Affected:
- up to 6.4.4
- Fixed in:
- 6.4.5
- Disclosed:
- May 12, 2023
CVE-2023-33333 on NVD →
Complianz – GDPR/CCPA Cookie Consent [complianz-gdpr] < 6.4.5
unknown
The Complianz - GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.4.4. This is due to missing or incorrect nonce validation on the maybe_install_suggested_plugins function. This makes it possible for unauthenticated attackers to install suggest...
- Affected:
- up to 6.4.5
- Fixed in:
- 6.4.5
- Disclosed:
- May 12, 2023
Complianz – GDPR/CCPA Cookie Consent [complianz-gdpr] < 6.4.5
unknown
The Complianz - GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.4.4. This is due to missing or incorrect nonce validation on the ajax_script_save function. This makes it possible for unauthenticated attackers to save scripts via a forged requ...
- Affected:
- up to 6.4.5
- Fixed in:
- 6.4.5
- Disclosed:
- May 12, 2023
Complianz – GDPR/CCPA Cookie Consent [complianz-gdpr] < 6.4.5
unknown
The Complianz - GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.4.4. This is due to missing or incorrect nonce validation on the cmplz_duplicate_cookiebanner function. This makes it possible for unauthenticated attackers to duplicate the comp...
- Affected:
- up to 6.4.5
- Fixed in:
- 6.4.5
- Disclosed:
- May 12, 2023
Complianz – GDPR/CCPA Cookie Consent [complianz-gdpr] < 6.4.5
unknown
The Complianz - GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.4.4. This is due to missing or incorrect nonce validation on the cmplz_delete_cookiebanner function. This makes it possible for unauthenticated attackers to delete the compliance...
- Affected:
- up to 6.4.5
- Fixed in:
- 6.4.5
- Disclosed:
- May 12, 2023
Complianz – GDPR/CCPA Cookie Consent [complianz-gdpr] < 6.4.2
unknown
[en] The Complianz WordPress plugin before 6.4.2, Complianz Premium WordPress plugin before 6.4.2 do not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site...
- Affected:
- up to 6.4.2
- Fixed in:
- 6.4.2
- Disclosed:
- Mar 27, 2023
CVE-2023-1069 on NVD →
Complianz - GDPR/CCPA Cookie Consent <= 6.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Complianz - GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in versions up to, and including, 6.4.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with co...
- CVSS:
- 6.4
- Affected:
- up to 6.4.1
- Fixed in:
- 6.4.2
- Disclosed:
- Mar 6, 2023
CVE-2023-1069 on NVD →
Complianz – GDPR/CCPA Cookie Consent [complianz-gdpr] < 6.3.4
unknown
[en] The Complianz WordPress plugin before 6.3.4, and Complianz Premium WordPress plugin before 6.3.6 allow a translators to inject arbitrary SQL through an unsanitized translation. SQL can be injected through an infected translation file, or by a user with a translator role through translation plugins such as Loco Tra...
- Affected:
- up to 6.3.4
- Fixed in:
- 6.3.4
- Disclosed:
- Nov 7, 2022
CVE-2022-3494 on NVD →
Complianz Free <= 6.3.3 & Premium <= 6.3.5 - SQL Injection via Translations
high
The Complianz plugin for WordPress is vulnerable to SQL Injection via unescaped translations in versions up to, and including, 6.3.3 (Free) and 6.3.5 (Premium) due to insufficient escaping on the user supplied translation (either from a translation file or a user with translator role through a translation plugin) and l...
- CVSS:
- 8.8
- Affected:
- up to 6.3.3
- Fixed in:
- 6.3.4
- Disclosed:
- Oct 17, 2022
CVE-2022-3494 on NVD →
Complianz – GDPR/CCPA Cookie Consent [complianz-gdpr] < 6.0.0
unknown
[en] The Complianz WordPress plugin before 6.0.0 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting
- Affected:
- up to 6.0.0
- Fixed in:
- 6.0.0
- Disclosed:
- Feb 14, 2022
CVE-2022-0193 on NVD →
Complianz - GDPR/CCPA Cookie Consent <= 5.5.2 - Reflected Cross-Site Scripting via s parameter
medium
The Complianz WordPress plugin before 6.0.0 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting
- CVSS:
- 6.1
- Affected:
- up to 6.0.0
- Fixed in:
- 6.0.0
- Disclosed:
- Jan 17, 2022
CVE-2022-0193 on NVD →