plugin

Cookiebot Vulnerabilities

16 known security issues reported for the Cookiebot WordPress plugin. Most recent disclosed Feb 19, 2026.

9 medium

Running Cookiebot on your site? Check whether your installed version is affected.

Scan your site free

Cookiebot by Usercentrics &#8211; Automatic Cookie Banner for GDPR/CCPA &amp; Google Consent Mode [cookiebot] <= 4.6.4 (unfixed)

unknown

[en] Missing Authorization vulnerability in cookiebot Cookiebot cookiebot allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cookiebot: from n/a through <= 4.6.4.

Affected:
up to 4.6.4
Fix:
No patched version reported
Disclosed:
Feb 19, 2026

CVE-2026-25407 on NVD →

Cookiebot by Usercentrics – Automatic Cookie Banner for GDPR/CCPA & Google Consent Mode <= 4.6.4 - Missing Authorization

medium

The Cookiebot by Usercentrics – Automatic Cookie Banner for GDPR/CCPA & Google Consent Mode plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.6.4. This makes it possible for authenticated attackers, with subscriber-level access...

CVSS:
4.3
Affected:
up to 4.6.4
Fixed in:
4.6.5
Disclosed:
Jan 29, 2026

CVE-2026-25407 on NVD →

Cookiebot by Usercentrics – Automatic Cookie Banner for GDPR/CCPA & Google Consent Mode < 4.6.5 - Missing Authorization

medium
Affected:
up to 4.6.5
Fixed in:
4.6.5
Disclosed:
Jan 29, 2026

CVE-2026-25407 on NVD →

Cookiebot <= 4.5.8 - Cross-Site Request Forgery

medium

The Usercentrics Cookiebot – Automatic Cookie Banner for GDPR/CCPA & Google Consent Mode plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5.8. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers...

CVSS:
4.3
Affected:
up to 4.5.8
Fixed in:
4.5.9
Disclosed:
Jun 27, 2025

CVE-2025-53197 on NVD →

Cookiebot < 4.5.9 - Cross-Site Request Forgery

medium
Affected:
up to 4.5.9
Fixed in:
4.5.9
Disclosed:
Jun 27, 2025

CVE-2025-53197 on NVD →

Cookiebot by Usercentrics &#8211; Automatic Cookie Banner for GDPR/CCPA &amp; Google Consent Mode [cookiebot] < 4.5.9

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in cookiebot Cookiebot allows Cross Site Request Forgery. This issue affects Cookiebot: from n/a through 4.5.8.

Affected:
up to 4.5.9
Fixed in:
4.5.9
Disclosed:
Jun 27, 2025

CVE-2025-53197 on NVD →

Cookie banner plugin for WordPress – Cookiebot CMP by Usercentrics <= 4.4.1 - Missing Authorization to Authenticated (Subscriber+) Survey Submission

medium

The Cookie banner plugin for WordPress – Cookiebot CMP by Usercentrics plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the send_uninstall_survey() function in all versions up to, and including, 4.4.1. This makes it possible for authenticated attackers, with S...

CVSS:
4.3
Affected:
up to 4.4.1
Fixed in:
4.4.2
Disclosed:
Mar 5, 2025

CVE-2025-1666 on NVD →

Cookie banner plugin for WordPress – Cookiebot CMP by Usercentrics < 4.4.2 - Missing Authorization to Authenticated (Subscriber+) Survey Submission

medium
Affected:
up to 4.4.2
Fixed in:
4.4.2
Disclosed:
Mar 5, 2025

CVE-2025-1666 on NVD →

Cookiebot < 3.6.1 - CSRF & XSS

medium
Affected:
up to 3.6.1
Fixed in:
3.6.1
Disclosed:
Sep 9, 2020

Cookiebot by Usercentrics &#8211; Automatic Cookie Banner for GDPR/CCPA &amp; Google Consent Mode [cookiebot] < 3.6.1

unknown

Reflected Cross-Site Scripting (XSS) vulnerability found by Antony Garand (Sucuri) in WordPress Cookiebot plugin (versions <= 3.6.0).

Affected:
up to 3.6.1
Fixed in:
3.6.1
Disclosed:
Sep 9, 2020

Cookiebot | GDPR/CCPA Compliant Cookie Consent and Control <= 3.6.0 - Reflected Cross-Site Scripting

medium

The Cookiebot | GDPR/CCPA Compliant Cookie Consent and Control plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the tab parameter in versions up to, and including 3.6.0 This makes it possible for unauthenticated attackers to inject arbitrary web scripts in administrative pages that execute if th...

CVSS:
6.1
Affected:
up to 3.6.1
Fixed in:
3.6.1
Disclosed:
Sep 8, 2020

Cookiebot by Usercentrics &#8211; Automatic Cookie Banner for GDPR/CCPA &amp; Google Consent Mode [cookiebot] < 3.6.1

unknown

The Cookiebot | GDPR/CCPA Compliant Cookie Consent and Control plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the tab parameter in versions up to, and including 3.6.0 This makes it possible for unauthenticated attackers to inject arbitrary web scripts in administrative pages that execute if th...

Affected:
up to 3.6.1
Fixed in:
3.6.1
Disclosed:
Sep 8, 2020

Cookiebot < 3.6.1 - Authenticated Reflected Cross-Site Scripting (XSS)

medium
Affected:
up to 3.6.1
Fixed in:
3.6.1
Disclosed:
Mar 23, 2020

Cookiebot by Usercentrics &#8211; Automatic Cookie Banner for GDPR/CCPA &amp; Google Consent Mode [cookiebot] < 3.6.1

unknown

Antony Garand of Sucuri discovered that multiple WordPress plugins were vulnerable to Cross-Site Scripting (XSS) within the admin panel, which could be exploited by using s Cross-Site Request Forgery (CSRF) attack.

Affected:
up to 3.6.1
Fixed in:
3.6.1

Cookiebot by Usercentrics &#8211; Automatic Cookie Banner for GDPR/CCPA &amp; Google Consent Mode [cookiebot] < 3.6.1

unknown

Versions prior to 3.6.1 are susceptible to this attack, which allows hackers to exploit the vulnerability found on administrative pages.

Affected:
up to 3.6.1
Fixed in:
3.6.1

Cookiebot by Usercentrics &#8211; Automatic Cookie Banner for GDPR/CCPA &amp; Google Consent Mode [cookiebot] < 4.4.2

unknown
Affected:
up to 4.4.2
Fixed in:
4.4.2

CVE-2025-1666 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database