plugin

Wp Gdpr Cookie Consent Vulnerabilities

1 known security issue reported for the Wp Gdpr Cookie Consent WordPress plugin. Most recent disclosed Jun 8, 2026.

1 medium

Running Wp Gdpr Cookie Consent on your site? Check whether your installed version is affected.

Scan your site free

WP GDPR Cookie Consent <= 1.0.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'ninja_gdpr_ajax_actions' AJAX Action

medium

The WP GDPR Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ninja_gdpr_ajax_actions' AJAX action in versions up to, and including, 1.0.0. This is due to missing capability and nonce checks on the handleAjaxCalls() function, combined with insufficient input sanitization on the g...

CVSS:
6.4
Affected:
up to 1.0.0
Fix:
No patched version reported
Disclosed:
Jun 8, 2026

CVE-2026-8977 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database