← WordPress Vulnerabilities
WordPress security by component

WP Cookie Notice for GDPR, CCPA & ePrivacy Consent

WP Cookie Notice for GDPR, CCPA & ePrivacy Consent displays cookie consent notices and provides settings for managing visitor consent preferences on WordPress websites.

WP Cookie Notice for GDPR, CCPA & ePrivacy Consent (gdpr-cookie-consent) is a WordPress plugin with 22 published CVE records in this archive. The latest tracked vulnerability was published Sep 17, 2026; the highest published CVSS base score is 10.

Plugin slug: gdpr-cookie-consent

CVE-2026-85130: WPLP Cookie Consent stores public input as executable admin-side JavaScript on multisite

WPLP Cookie Consent before 4.4.4 accepts a value at a public endpoint, logs it and later emits it on an administrative screen without JavaScript-context escaping. An unauthenticated attacker can store script that executes in an administrator's session when the administrator interacts with the logged entry. Only multisite installations are affected. The export does not identify the endpoint, input field, logging function or required interaction.

PublishedSep 17, 2026
Known safe version4.4.4
Published vulnerabilities for gdpr-cookie-consent
Safe version
Sep 17, 2026 CVE-2026-85130
WPLP Cookie Consent stores public input as executable admin-side JavaScript on multisite
WPLP Cookie Consent before 4.4.4 accepts a value at a public endpoint, logs it and later emits it on an administrative screen without JavaScript-context escaping. An unauthenticated attacker can store script that executes in an administrator's session when the administrator interacts with the logged entry. Only multisite installations are affected. The export does not identify the endpoint, input field, logging function or required interaction.
4.4.4
CVE8.8
NVDPending
Sep 16, 2026 CVE-2026-85131
WPLP Cookie Consent allows forged admin bulk actions to delete unrelated posts
WPLP Cookie Consent before 4.4.4: An attacker can trick a logged-in administrator into submitting a bulk-action request. The handler lacks both CSRF and capability checks and fails to limit targets to the plugin's own records, allowing permanent deletion of arbitrary posts and pages. The export does not name the action, target-ID field or handler.
4.4.4
CVE6.5
NVDPending
Sep 09, 2026 CVE-2026-14989
WPLP Cookie Consent stores unauthenticated scripts in consent preferences
WPLP Cookie Consent through 4.4.1 inadequately sanitizes and escapes wpl_user_preference. Its consent-logging AJAX action accepts unauthenticated requests, and wpl_consent_logging_nonce is exposed publicly through wp_localize_script. A visitor can therefore submit stored scripts that execute when another user views the affected content.
See mitigation notes
CVE7.2
NVDPending
Sep 01, 2026 CVE-2026-75865
WPLP Cookie Consent permits unauthenticated arbitrary file upload
WPLP Cookie Consent through 4.4.1 combines an authorization bypass on its connector REST endpoints with missing file-type validation in saas_upload_logo(). An unauthenticated attacker can upload arbitrary files to the server, potentially leading to remote code execution.
See mitigation notes
CVE9.8
NVDPending
Aug 31, 2026 CVE-2026-82970
WP Cookie Notice permits unauthenticated arbitrary file upload
WP Cookie Notice for GDPR, CCPA & ePrivacy Consent through 4.4.1 allows an unauthenticated attacker to upload a dangerous file. Attacker-controlled executable content can lead to arbitrary code execution and full site compromise.
4.4.2
CVE10.0
NVDPending
Aug 18, 2026 CVE-2026-73359
WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: Cross-site scripting
WP Cookie Notice for GDPR, CCPA & ePrivacy Consent is affected by cross-site scripting. Exploitation requires an authenticated subscriber account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 4.3.9.
4.4.0
CVE6.5
NVDPending
Aug 15, 2026 CVE-2026-13360
WPLP Cookie Consent regionArray permits stored XSS
WPLP Cookie Consent through 4.3.5 stores the regionArray value without adequate sanitization and later renders it without sufficient escaping. The affected AJAX handler lacks a capability and nonce check; the CNA describes unauthenticated injection and also confirms that any Subscriber can overwrite the setting. Successful exploitation requires the non-default Google Consent Mode support option to be enabled. The action name, output sink, and payload are not disclosed.
See mitigation notes
CVE7.2
NVDPending
Jul 28, 2026 CVE-2026-15136
WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode: Cross-site request forgery
WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is <= 4.3.7.
See mitigation notes
CVE4.3
NVDPending
Jul 10, 2026 CVE-2026-14475
Cookie Banner for GDPR / CCPA – WPLP Cookie Consent: SQL injection
Cookie Banner for GDPR / CCPA – WPLP Cookie Consent is affected by SQL injection. Exploitation requires an authenticated administrator account. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 4.3.6.
See mitigation notes
CVE4.9
NVDPending
Jul 10, 2026 CVE-2026-12955
Cookie Banner for GDPR / CCPA – WPLP Cookie Consent: A security weakness
Cookie Banner for GDPR / CCPA – WPLP Cookie Consent is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 4.3.6.
See mitigation notes
CVE4.3
NVDPending
Jul 03, 2026 CVE-2026-12920
Cookie Banner for GDPR / CCPA – WPLP Cookie Consent: SQL injection
Cookie Banner for GDPR / CCPA – WPLP Cookie Consent is affected by SQL injection. Exploitation requires an authenticated administrator account. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 4.3.5.
See mitigation notes
CVE4.9
NVDPending
Feb 19, 2026 CVE-2025-11754
GDPR Cookie Consent: A security weakness
GDPR Cookie Consent is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVDPending
Dec 30, 2025 CVE-2025-66080
WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: A security weakness
WP Cookie Notice for GDPR, CCPA & ePrivacy Consent is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Dec 17, 2025 CVE-2025-14061
Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Consent: A security weakness
Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Consent is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Dec 16, 2025 CVE-2025-66133
WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: A security weakness
WP Cookie Notice for GDPR, CCPA & ePrivacy Consent is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Nov 21, 2025 CVE-2025-66075
WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: A security weakness
WP Cookie Notice for GDPR, CCPA & ePrivacy Consent is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Jun 06, 2025 CVE-2025-49285
WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: Cross-site request forgery
WP Cookie Notice for GDPR, CCPA & ePrivacy Consent is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
May 15, 2025 CVE-2024-8397
webtoffee-gdpr-cookie-consent: Cross-site scripting
webtoffee-gdpr-cookie-consent is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVDPending
May 15, 2025 CVE-2024-8286
webtoffee-gdpr-cookie-consent: Cross-site request forgery
webtoffee-gdpr-cookie-consent is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE6.5
NVDPending
Jun 26, 2024 CVE-2024-4869
WP Cookie Consent ( for GDPR, CCPA & ePrivacy ): Cross-site scripting
WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.2
NVD6.1
Nov 07, 2023 CVE-2023-23678
WP Cookie Consent ( for GDPR, CCPA & ePrivacy ): A security weakness
WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.0
NVD7.2
Aug 21, 2020 CVE-2020-20633
Gdpr Cookie Consent: Cross-site scripting
Gdpr Cookie Consent is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD5.4