plugin

Gdpr Cookie Compliance Vulnerabilities

10 known security issues reported for the Gdpr Cookie Compliance WordPress plugin. Most recent disclosed Jul 27, 2026.

10 medium

Running Gdpr Cookie Compliance on your site? Check whether your installed version is affected.

Scan your site free

GDPR Cookie Compliance <= 5.0.0 - Cross-Site Request Forgery

medium

The GDPR Cookie Compliance plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.0.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted the...

CVSS:
4.3
Affected:
up to 5.0.0
Fixed in:
5.1.0
Disclosed:
Jul 27, 2026

CVE-2026-16613 on NVD →

GDPR Cookie Compliance <= 4.15.6 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The GDPR Cookie Compliance – Cookie Banner, Cookie Consent, Cookie Notice – CCPA, DSGVO, RGPD plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.15.6 due to insufficient input sanitization and output escaping. This makes it possible for authentic...

CVSS:
4.4
Affected:
up to 4.15.6
Fixed in:
4.15.7
Disclosed:
Feb 23, 2025

CVE-2025-2205 on NVD →

GDPR Cookie Compliance <= 4.15.6 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The GDPR Cookie Compliance – Cookie Banner, Cookie Consent, Cookie Notice – CCPA, DSGVO, RGPD plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.15.6 due to insufficient input sanitization and output escaping. This makes it possible for authentic...

CVSS:
4.4
Affected:
up to 4.15.6
Fixed in:
4.15.7
Disclosed:
Feb 23, 2025

CVE-2025-1622 on NVD →

GDPR Cookie Compliance <= 4.15.6 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The GDPR Cookie Compliance – Cookie Banner, Cookie Consent, Cookie Notice – CCPA, DSGVO, RGPD plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.15.6 due to insufficient input sanitization and output escaping. This makes it possible for authentic...

CVSS:
4.4
Affected:
up to 4.15.6
Fixed in:
4.15.7
Disclosed:
Feb 23, 2025

CVE-2025-1620 on NVD →

GDPR Cookie Compliance <= 4.15.6 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The GDPR Cookie Compliance – Cookie Banner, Cookie Consent, Cookie Notice – CCPA, DSGVO, RGPD plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.15.6 due to insufficient input sanitization and output escaping. This makes it possible for authentic...

CVSS:
4.4
Affected:
up to 4.15.6
Fixed in:
4.15.7
Disclosed:
Feb 23, 2025

CVE-2025-1619 on NVD →

GDPR Cookie Compliance <= 4.15.6 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The GDPR Cookie Compliance – Cookie Banner, Cookie Consent, Cookie Notice – CCPA, DSGVO, RGPD plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.15.6 due to insufficient input sanitization and output escaping. This makes it possible for authentic...

CVSS:
4.4
Affected:
up to 4.15.6
Fixed in:
4.15.7
Disclosed:
Feb 23, 2025

CVE-2025-1621 on NVD →

GDPR Cookie Compliance <= 4.15.8 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The GDPR Cookie Compliance – Cookie Banner, Cookie Consent, Cookie Notice – CCPA, DSGVO, RGPD plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.15.8 due to insufficient input sanitization and output escaping. This makes it possible for authentic...

CVSS:
4.4
Affected:
up to 4.15.8
Fixed in:
4.15.9
Disclosed:
Feb 23, 2025

CVE-2025-1624 on NVD →

GDPR Cookie Compliance <= 4.15.8 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The GDPR Cookie Compliance – Cookie Banner, Cookie Consent, Cookie Notice – CCPA, DSGVO, RGPD plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.15.8 due to insufficient input sanitization and output escaping. This makes it possible for authentic...

CVSS:
4.4
Affected:
up to 4.15.8
Fixed in:
4.15.9
Disclosed:
Feb 23, 2025

CVE-2025-1623 on NVD →

GDPR Cookie Compliance <= 4.12.4 - Cross-Site Request Forgery to License Modification

medium

The GDPR Cookie Compliance plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.12.4. This is due to missing nonce validation in the /views/moove/admin/settings/licence.php file. This makes it possible for unauthenticated attackers to update and deactivate the plugin's li...

CVSS:
4.3
Affected:
up to 4.12.4
Fixed in:
4.12.5
Disclosed:
Aug 7, 2023

CVE-2023-4013 on NVD →

GDPR Cookie Compliance <= 4.0.2 - Missing Authorization

medium

The GDPR Cookie Compliance plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the gdpr_cookie_compliance_reset_settings AJAX action in versions up to, and including, 4.0.2. This makes it possible for authenticated attackers to reset all of the settings.

CVSS:
5.4
Affected:
up to 4.0.2
Fixed in:
4.0.3
Disclosed:
Dec 27, 2019

CVE-2019-25143 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database