← WordPress Vulnerabilities
WordPress security by component

WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode

WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode is a WordPress component with 15 published CVE records in this archive. The latest tracked vulnerability was published Jul 28, 2026; the highest CVE/CNA score is 7.5.

Plugin slug: gdpr-cookie-consent

CVE-2026-15136: WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode: Cross-site request forgery

WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is <= 4.3.7.

PublishedJul 28, 2026
Known safe version> 4.3.7
Safe version
Jul 28, 2026 CVE-2026-15136
WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode: Cross-site request forgery
WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is <= 4.3.7.
> 4.3.7
CVE4.3
NVDPending
Jul 10, 2026 CVE-2026-14475
Cookie Banner for GDPR / CCPA – WPLP Cookie Consent: SQL injection
Cookie Banner for GDPR / CCPA – WPLP Cookie Consent is affected by SQL injection. Exploitation requires at least administrator-level access. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 4.3.6.
> 4.3.6
CVE4.9
NVDPending
Jul 10, 2026 CVE-2026-12955
Cookie Banner for GDPR / CCPA – WPLP Cookie Consent: A security weakness
Cookie Banner for GDPR / CCPA – WPLP Cookie Consent is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 4.3.6.
> 4.3.6
CVE4.3
NVDPending
Jul 03, 2026 CVE-2026-12920
Cookie Banner for GDPR / CCPA – WPLP Cookie Consent: SQL injection
Cookie Banner for GDPR / CCPA – WPLP Cookie Consent is affected by SQL injection. Exploitation requires at least administrator-level access. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 4.3.5.
> 4.3.5
CVE4.9
NVDPending
Feb 19, 2026 CVE-2025-11754
GDPR Cookie Consent: A security weakness
GDPR Cookie Consent is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVDPending
Dec 30, 2025 CVE-2025-66080
WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: A security weakness
WP Cookie Notice for GDPR, CCPA & ePrivacy Consent is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Dec 17, 2025 CVE-2025-14061
Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Consent: A security weakness
Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Consent is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Dec 16, 2025 CVE-2025-66133
WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: A security weakness
WP Cookie Notice for GDPR, CCPA & ePrivacy Consent is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Nov 21, 2025 CVE-2025-66075
WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: A security weakness
WP Cookie Notice for GDPR, CCPA & ePrivacy Consent is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Jun 06, 2025 CVE-2025-49285
WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: Cross-site request forgery
WP Cookie Notice for GDPR, CCPA & ePrivacy Consent is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
May 15, 2025 CVE-2024-8397
webtoffee-gdpr-cookie-consent: Cross-site scripting
webtoffee-gdpr-cookie-consent is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVDPending
May 15, 2025 CVE-2024-8286
webtoffee-gdpr-cookie-consent: Cross-site request forgery
webtoffee-gdpr-cookie-consent is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE6.5
NVDPending
Jun 26, 2024 CVE-2024-4869
WP Cookie Consent ( for GDPR, CCPA & ePrivacy ): Cross-site scripting
WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.2
NVD6.1
Nov 07, 2023 CVE-2023-23678
WP Cookie Consent ( for GDPR, CCPA & ePrivacy ): A security weakness
WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.0
NVD7.2
Aug 21, 2020 CVE-2020-20633
Gdpr Cookie Consent: Cross-site scripting
Gdpr Cookie Consent is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4