GDPR CCPA Compliance Support <= 2.7.4 - Missing Authorization
medium
The GDPR CCPA Compliance & Cookie Consent Banner plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.7.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized a...
- CVSS:
- 4.3
- Affected:
- up to 2.7.4
- Fixed in:
- 2.7.5
- Disclosed:
- Jan 19, 2026
CVE-2025-68073 on NVD →
GDPR CCPA Compliance Support <= 2.7.3 - Missing Authorization
medium
The GDPR CCPA Compliance & Cookie Consent Banner plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.7.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized a...
- CVSS:
- 4.3
- Affected:
- up to 2.7.3
- Fixed in:
- 2.7.4
- Disclosed:
- May 19, 2025
CVE-2025-48260 on NVD →
GDPR CCPA Compliance Support <= 2.7.1 - Missing Authorization
medium
The GDPR CCPA Compliance & Cookie Consent Banner plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.7.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform an unauthorized...
- CVSS:
- 4.3
- Affected:
- up to 2.7.1
- Fixed in:
- 2.7.2
- Disclosed:
- Jan 24, 2025
CVE-2025-24591 on NVD →
GDPR CCPA Compliance & Cookie Consent Banner <= 2.7.0 - Missing Authorization to Settings Update and Stored Cross-Site Scripting
medium
The GDPR CCPA Compliance & Cookie Consent Banner plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions named ajaxUpdateSettings() in all versions up to, and including, 2.7.0. This makes it possible for authenticated attackers, with Subscriber-leve...
- CVSS:
- 5.4
- Affected:
- up to 2.7.0
- Fixed in:
- 2.7.1
- Disclosed:
- Jun 6, 2024
CVE-2024-5607 on NVD →
GDPR CCPA Compliance Support <= 2.3 - PHP Object Injection
critical
The GDPR CCPA Compliance Support plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.3 via deserialization of untrusted input "njt_gdpr_allow_permissions" value. This allows unauthenticated attackers to inject a PHP Object.
- CVSS:
- 9.8
- Affected:
- up to 2.3
- Fixed in:
- 2.4
- Disclosed:
- Nov 3, 2020
CVE-2020-36718 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database