plugin

Cookie Notice And Consent Banner Vulnerabilities

2 known security issues reported for the Cookie Notice And Consent Banner WordPress plugin. Most recent disclosed Sep 3, 2025.

2 medium

Running Cookie Notice And Consent Banner on your site? Check whether your installed version is affected.

Scan your site free

Cookie Notice &amp; Consent Banner for GDPR &amp; CCPA Compliance <= 1.7.11 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Cookie Notice &amp; Consent Banner for GDPR &amp; CCPA Compliance plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access a...

CVSS:
6.4
Affected:
up to 1.7.11
Fixed in:
1.7.12
Disclosed:
Sep 3, 2025

CVE-2025-58607 on NVD →

Cookie Notice & Consent Banner for GDPR & CCPA Compliance <= 1.7.1 - Authenticated Stored Cross-Site Scripting

medium

The Cookie Notice & Consent Banner for GDPR & CCPA Compliance WordPress plugin before 1.7.2 does not properly sanitize inputs to prevent injection of arbitrary HTML within the plugin's design customization options.

CVSS:
5.4
Affected:
up to 1.7.2
Fixed in:
1.7.2
Disclosed:
Aug 6, 2021

CVE-2021-24590 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database