WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode <= 4.3.9 - Authenticated (Subscriber+) Stored Cross-Site Scripting
medium
The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.3.9. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated at...
- CVSS:
- 6.4
- Affected:
- up to 4.3.9
- Fixed in:
- 4.4.0
- Disclosed:
- Aug 18, 2026
CVE-2026-73359 on NVD →
Cookie Banner for GDPR / CCPA <= 4.3.5 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'regionArray' Parameter
high
The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'regionArray' parameter in all versions up to, and including, 4.3.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject...
- CVSS:
- 7.2
- Affected:
- up to 4.3.5
- Fixed in:
- 4.4.0
- Disclosed:
- Aug 14, 2026
CVE-2026-13360 on NVD →
Cookie Banner for GDPR / CCPA – WPLP Cookie Consent <= 4.3.7 - Cross-Site Request Forgery via Bulk Action to Delete/Resolve Entries
medium
The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.3.7. This is due to missing or incorrect nonce validation on the process_bulk_action function. This makes it possible for unauthenticated attackers to permanen...
- CVSS:
- 4.3
- Affected:
- up to 4.3.7
- Fixed in:
- 4.3.8
- Disclosed:
- Jul 27, 2026
CVE-2026-15136 on NVD →
Cookie Banner for GDPR / CCPA <= 4.3.6 - Authenticated (Administrator+) SQL Injection via 'scan_id' Parameter
medium
The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to generic SQL Injection via the 'scan_id' parameter in all versions up to, and including, 4.3.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes...
- CVSS:
- 4.9
- Affected:
- up to 4.3.6
- Fixed in:
- 4.3.7
- Disclosed:
- Jul 9, 2026
CVE-2026-14475 on NVD →
Cookie Banner for GDPR / CCPA <= 4.3.6 - Missing Authorization to Authenticated (Subscriber+) Scan Schedule Modification via gcc_save_schedule_scan AJAX Action
medium
The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the gdpr_cookie_consent_ajax_save_schedule_scan() function (the wp_ajax_gcc_save_schedule_scan AJAX action) in versions up to, and including, 4.3.6. This ma...
- CVSS:
- 4.3
- Affected:
- up to 4.3.6
- Fixed in:
- 4.3.7
- Disclosed:
- Jul 9, 2026
CVE-2026-12955 on NVD →
Cookie Banner for GDPR / CCPA <= 4.3.5 - Authenticated (Administrator+) SQL Injection via 's' Parameter
medium
The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, and including, 4.3.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it po...
- CVSS:
- 4.9
- Affected:
- up to 4.3.5
- Fixed in:
- 4.3.6
- Disclosed:
- Jul 2, 2026
CVE-2026-12920 on NVD →
Cookie Banner for GDPR / CCPA – WPLP Cookie Consent [gdpr-cookie-consent] < 4.1.3
unknown
[en] The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'gdpr/v1/settings' REST API endpoint in all versions up to, and including, 4.1.2. This makes it possible for unauthenticated attackers to retrieve sensitive plugin settings including A...
- Affected:
- up to 4.1.3
- Fixed in:
- 4.1.3
- Disclosed:
- Feb 19, 2026
CVE-2025-11754 on NVD →
Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Consent <= 4.1.2 - Missing Authorization to Sensitive Information Exposure
high
The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'gdpr/v1/settings' REST API endpoint in all versions up to, and including, 4.1.2. This makes it possible for unauthenticated attackers to retrieve sensitive plugin settings including API to...
- CVSS:
- 7.5
- Affected:
- up to 4.1.2
- Fixed in:
- 4.1.3
- Disclosed:
- Feb 18, 2026
CVE-2025-11754 on NVD →
Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.0.3 - Missing Authorization
medium
The Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpl_data_req_process_delete() function in versions up to, and including, 4.0.3. This makes it possible for unauthenticated attackers to delete data.
- CVSS:
- 5.3
- Affected:
- up to 4.0.3
- Fixed in:
- 4.0.4
- Disclosed:
- Dec 30, 2025
CVE-2025-66080 on NVD →
Cookie Banner for GDPR / CCPA – WPLP Cookie Consent [gdpr-cookie-consent] <= 4.0.3 (unfixed)
unknown
[en] Missing Authorization vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through 4.0.3.
- Affected:
- up to 4.0.3
- Fix:
- No patched version reported
- Disclosed:
- Dec 30, 2025
CVE-2025-66080 on NVD →
Cookie Banner for GDPR / CCPA – WPLP Cookie Consent [gdpr-cookie-consent] < 4.0.8
unknown
[en] The Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Consent plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the gdpr_delete_policy_data function in all versions up to, and including, 4.0.7....
- Affected:
- up to 4.0.8
- Fixed in:
- 4.0.8
- Disclosed:
- Dec 17, 2025
CVE-2025-14061 on NVD →
Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Consent <= 4.0.7 - Missing Authorization to Unauthenticated Arbitrary Post Deletion
medium
The Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Consent plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the gdpr_delete_policy_data function in all versions up to, and including, 4.0.7. This...
- CVSS:
- 5.3
- Affected:
- up to 4.0.7
- Fixed in:
- 4.0.8
- Disclosed:
- Dec 16, 2025
CVE-2025-14061 on NVD →
Cookie Banner for GDPR / CCPA – WPLP Cookie Consent [gdpr-cookie-consent] <= 4.0.7 (unfixed)
unknown
[en] Missing Authorization vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent gdpr-cookie-consent allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through <= 4.0.7.
- Affected:
- up to 4.0.7
- Fix:
- No patched version reported
- Disclosed:
- Dec 16, 2025
CVE-2025-66133 on NVD →
Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.0.7 - Missing Authorization
medium
The Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Consent plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.0.7. This makes it possible for unauthenticated...
- CVSS:
- 5.3
- Affected:
- up to 4.0.7
- Fixed in:
- 4.0.8
- Disclosed:
- Dec 15, 2025
CVE-2025-66133 on NVD →
Cookie Banner for GDPR / CCPA – WPLP Cookie Consent [gdpr-cookie-consent] <= 4.0.3 (unfixed)
unknown
[en] Missing Authorization vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent gdpr-cookie-consent allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through <= 4.0.3.
- Affected:
- up to 4.0.3
- Fix:
- No patched version reported
- Disclosed:
- Nov 21, 2025
CVE-2025-66075 on NVD →
Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.0.3 - Missing Authorization
medium
The Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Consent plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.0.3. This makes it possible for authenticated a...
- CVSS:
- 4.3
- Affected:
- up to 4.0.3
- Fixed in:
- 4.0.4
- Disclosed:
- Nov 8, 2025
CVE-2025-66075 on NVD →
Cookie Banner for GDPR / CCPA – WPLP Cookie Consent [gdpr-cookie-consent] < 3.8.1
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent allows Cross Site Request Forgery. This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through 3.8.0.
- Affected:
- up to 3.8.1
- Fixed in:
- 3.8.1
- Disclosed:
- Jun 6, 2025
CVE-2025-49285 on NVD →
WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 3.8.0 - Cross-Site Request Forgery
medium
The Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.0. This is due to missing or incorrect nonce validation on a function. This makes it p...
- CVSS:
- 4.3
- Affected:
- up to 3.8.0
- Fixed in:
- 3.8.1
- Disclosed:
- Jun 5, 2025
CVE-2025-49285 on NVD →
Cookie Banner for GDPR / CCPA – WPLP Cookie Consent [gdpr-cookie-consent] < 3.6.6
unknown
[en] The Cookie Consent for WP – Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpl_script_save AJAX action in all versions up to, and including, 3.6.5. This makes it...
- Affected:
- up to 3.6.6
- Fixed in:
- 3.6.6
- Disclosed:
- Dec 12, 2024
CVE-2024-11724 on NVD →
Cookie Consent for WP – Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) <= 3.6.5 - Missing Authorization to Authenticated (Subscriber+) Whitelist Script
medium
The Cookie Consent for WP – Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpl_script_save AJAX action in all versions up to, and including, 3.6.5. This makes it poss...
- CVSS:
- 4.3
- Affected:
- up to 3.6.5
- Fixed in:
- 3.6.6
- Disclosed:
- Dec 11, 2024
CVE-2024-11724 on NVD →
WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) <= 3.2.0 - Unauthenticated Stored Cross-Site Scripting via Client-IP header
high
The WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Client-IP’ header in all versions up to, and including, 3.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrar...
- CVSS:
- 7.2
- Affected:
- up to 3.2.0
- Fixed in:
- 3.3.0
- Disclosed:
- Jun 25, 2024
CVE-2024-4869 on NVD →
Cookie Banner for GDPR / CCPA – WPLP Cookie Consent [gdpr-cookie-consent] < 3.3.0
unknown
[en] The WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Client-IP’ header in all versions up to, and including, 3.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arb...
- Affected:
- up to 3.3.0
- Fixed in:
- 3.3.0
- Disclosed:
- Jun 25, 2024
CVE-2024-4869 on NVD →
Cookie Banner for GDPR / CCPA – WPLP Cookie Consent [gdpr-cookie-consent] < 3.1.0
unknown
[en] The WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the gdpr_policy_process_delete() function in all versions up to, and including, 3.0.2. This makes it possible for unauthenticated attackers to delete arbitrary po...
- Affected:
- up to 3.1.0
- Fixed in:
- 3.1.0
- Disclosed:
- May 2, 2024
CVE-2024-3599 on NVD →
WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) <= 3.0.2 - Missing Authorization to Unauthenticated Arbitrary Post Deletion
medium
The WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the gdpr_policy_process_delete() function in all versions up to, and including, 3.0.2. This makes it possible for unauthenticated attackers to delete arbitrary posts.
- CVSS:
- 5.3
- Affected:
- up to 3.0.2
- Fixed in:
- 3.1.0
- Disclosed:
- Apr 16, 2024
CVE-2024-3599 on NVD →
Cookie Banner for GDPR / CCPA – WPLP Cookie Consent [gdpr-cookie-consent] < 2.2.6
unknown
[en] Improper Neutralization of Formula Elements in a CSV File vulnerability in WPEkaClub WP Cookie Consent ( for GDPR, CCPA & ePrivacy ).This issue affects WP Cookie Consent ( for GDPR, CCPA & ePrivacy ): from n/a through 2.2.5.
- Affected:
- up to 2.2.6
- Fixed in:
- 2.2.6
- Disclosed:
- Nov 7, 2023
CVE-2023-23678 on NVD →
WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 2.2.5 - Authenticated(Administrator+) CSV Injection
medium
The WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 2.2.5. This allows authenticated administrators to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on...
- CVSS:
- 6.4
- Affected:
- up to 2.2.5
- Fixed in:
- 2.2.6
- Disclosed:
- Jun 20, 2023
CVE-2023-23678 on NVD →
Freemius SDK <= 2.4.2 - Missing Authorization Checks
medium
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...
- CVSS:
- 6.3
- Affected:
- up to 2.1.1
- Fixed in:
- 2.1.1
- Disclosed:
- Mar 4, 2022
CVE-2022-4974 on NVD →
Cookie Banner for GDPR / CCPA – WPLP Cookie Consent [gdpr-cookie-consent] < 2.1.1
unknown
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...
- Affected:
- up to 2.1.1
- Fixed in:
- 2.1.1
- Disclosed:
- Mar 4, 2022