Cookiebot by Usercentrics – Automatic Cookie Banner for GDPR/CCPA & Google Consent Mode [cookiebot] <= 4.6.4 (unfixed)
unknown
[en] Missing Authorization vulnerability in cookiebot Cookiebot cookiebot allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cookiebot: from n/a through <= 4.6.4.
- Affected:
- up to 4.6.4
- Fix:
- No patched version reported
- Disclosed:
- Feb 19, 2026
CVE-2026-25407 on NVD →
Cookiebot by Usercentrics – Automatic Cookie Banner for GDPR/CCPA & Google Consent Mode <= 4.6.4 - Missing Authorization
medium
The Cookiebot by Usercentrics – Automatic Cookie Banner for GDPR/CCPA & Google Consent Mode plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.6.4. This makes it possible for authenticated attackers, with subscriber-level access...
- CVSS:
- 4.3
- Affected:
- up to 4.6.4
- Fixed in:
- 4.6.5
- Disclosed:
- Jan 29, 2026
CVE-2026-25407 on NVD →
Cookiebot by Usercentrics – Automatic Cookie Banner for GDPR/CCPA & Google Consent Mode < 4.6.5 - Missing Authorization
medium
- Affected:
- up to 4.6.5
- Fixed in:
- 4.6.5
- Disclosed:
- Jan 29, 2026
CVE-2026-25407 on NVD →
Cookiebot <= 4.5.8 - Cross-Site Request Forgery
medium
The Usercentrics Cookiebot – Automatic Cookie Banner for GDPR/CCPA & Google Consent Mode plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5.8. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers...
- CVSS:
- 4.3
- Affected:
- up to 4.5.8
- Fixed in:
- 4.5.9
- Disclosed:
- Jun 27, 2025
CVE-2025-53197 on NVD →
Cookiebot < 4.5.9 - Cross-Site Request Forgery
medium
- Affected:
- up to 4.5.9
- Fixed in:
- 4.5.9
- Disclosed:
- Jun 27, 2025
CVE-2025-53197 on NVD →
Cookiebot by Usercentrics – Automatic Cookie Banner for GDPR/CCPA & Google Consent Mode [cookiebot] < 4.5.9
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in cookiebot Cookiebot allows Cross Site Request Forgery. This issue affects Cookiebot: from n/a through 4.5.8.
- Affected:
- up to 4.5.9
- Fixed in:
- 4.5.9
- Disclosed:
- Jun 27, 2025
CVE-2025-53197 on NVD →
Cookie banner plugin for WordPress – Cookiebot CMP by Usercentrics <= 4.4.1 - Missing Authorization to Authenticated (Subscriber+) Survey Submission
medium
The Cookie banner plugin for WordPress – Cookiebot CMP by Usercentrics plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the send_uninstall_survey() function in all versions up to, and including, 4.4.1. This makes it possible for authenticated attackers, with S...
- CVSS:
- 4.3
- Affected:
- up to 4.4.1
- Fixed in:
- 4.4.2
- Disclosed:
- Mar 5, 2025
CVE-2025-1666 on NVD →
Cookie banner plugin for WordPress – Cookiebot CMP by Usercentrics < 4.4.2 - Missing Authorization to Authenticated (Subscriber+) Survey Submission
medium
- Affected:
- up to 4.4.2
- Fixed in:
- 4.4.2
- Disclosed:
- Mar 5, 2025
CVE-2025-1666 on NVD →
Cookiebot < 3.6.1 - CSRF & XSS
medium
- Affected:
- up to 3.6.1
- Fixed in:
- 3.6.1
- Disclosed:
- Sep 9, 2020
Cookiebot by Usercentrics – Automatic Cookie Banner for GDPR/CCPA & Google Consent Mode [cookiebot] < 3.6.1
unknown
Reflected Cross-Site Scripting (XSS) vulnerability found by Antony Garand (Sucuri) in WordPress Cookiebot plugin (versions <= 3.6.0).
- Affected:
- up to 3.6.1
- Fixed in:
- 3.6.1
- Disclosed:
- Sep 9, 2020
Cookiebot | GDPR/CCPA Compliant Cookie Consent and Control <= 3.6.0 - Reflected Cross-Site Scripting
medium
The Cookiebot | GDPR/CCPA Compliant Cookie Consent and Control plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the tab parameter in versions up to, and including 3.6.0 This makes it possible for unauthenticated attackers to inject arbitrary web scripts in administrative pages that execute if th...
- CVSS:
- 6.1
- Affected:
- up to 3.6.1
- Fixed in:
- 3.6.1
- Disclosed:
- Sep 8, 2020
Cookiebot by Usercentrics – Automatic Cookie Banner for GDPR/CCPA & Google Consent Mode [cookiebot] < 3.6.1
unknown
The Cookiebot | GDPR/CCPA Compliant Cookie Consent and Control plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the tab parameter in versions up to, and including 3.6.0 This makes it possible for unauthenticated attackers to inject arbitrary web scripts in administrative pages that execute if th...
- Affected:
- up to 3.6.1
- Fixed in:
- 3.6.1
- Disclosed:
- Sep 8, 2020
Cookiebot < 3.6.1 - Authenticated Reflected Cross-Site Scripting (XSS)
medium
- Affected:
- up to 3.6.1
- Fixed in:
- 3.6.1
- Disclosed:
- Mar 23, 2020
Cookiebot by Usercentrics – Automatic Cookie Banner for GDPR/CCPA & Google Consent Mode [cookiebot] < 3.6.1
unknown
Antony Garand of Sucuri discovered that multiple WordPress plugins were vulnerable to Cross-Site Scripting (XSS) within the admin panel, which could be exploited by using s Cross-Site Request Forgery (CSRF) attack.
- Affected:
- up to 3.6.1
- Fixed in:
- 3.6.1
Cookiebot by Usercentrics – Automatic Cookie Banner for GDPR/CCPA & Google Consent Mode [cookiebot] < 3.6.1
unknown
Versions prior to 3.6.1 are susceptible to this attack, which allows hackers to exploit the vulnerability found on administrative pages.
- Affected:
- up to 3.6.1
- Fixed in:
- 3.6.1
Cookiebot by Usercentrics – Automatic Cookie Banner for GDPR/CCPA & Google Consent Mode [cookiebot] < 4.4.2
unknown
- Affected:
- up to 4.4.2
- Fixed in:
- 4.4.2
CVE-2025-1666 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database