Plugin Vulnerability Hub
Plugin 10 known issues Latest disclosed Feb 18, 2026

Cookie Banner for GDPR / CCPA – WPLP Cookie Consent Vulnerabilities

Review known vulnerability records for the WordPress plugin Cookie Banner for GDPR / CCPA – WPLP Cookie Consent (`gdpr-cookie-consent`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2025-11754, CVE-2025-66080 and CVE-2025-14061, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
10
High or Critical
2
Patch Coverage
100%
Last Updated
Feb 19, 2026
Related Security Guides

Use these guides while reviewing Cookie Banner for GDPR / CCPA – WPLP Cookie Consent fixes

Pair this plugin vulnerability hub with practical WordPress hardening, scanner, and patch workflow guidance.

Patch Decision Workflow

How to prioritize Cookie Banner for GDPR / CCPA – WPLP Cookie Consent remediation

Use the hub as a decision layer before opening individual records: confirm whether the issue has a CVE, whether a fixed version exists, and whether the affected range overlaps production installs.

Search-Ready Records
10
1. Match the Package
Confirm the installed WordPress plugin slug is gdpr-cookie-consent before acting on any CVE from this cluster.
2. Sort by Severity
Start with 2 high or critical records, then review medium and unrated findings with public references.
3. Check Patch Evidence
10 records include a patch path; verify compatibility before closing the finding.
4. Monitor Gaps
0 records still lack a listed fixed release, so keep this hub in the review queue.
Priority CVE Quick Links

Fast paths into Cookie Banner for GDPR / CCPA – WPLP Cookie Consent CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
10
Tracked CVE Issue Type Affected Versions Fixed Version CVSS
CVE-2025-11754
Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR...
Sensitive Information Exposure Versions up to 4.1.2 4.1.3 CVSS 7.5
CVE-2024-4869
WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) <= 3.2.0 - Unauthenticated Stored Cr...
Stored Cross-Site Scripting Versions up to 3.2.0 3.3.0 CVSS 7.2
CVE-2023-23678
WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 2.2.5 - Authenticated(Administ...
Vulnerability Versions up to 2.2.5 2.2.6 CVSS 6.4
CVE-2025-66080
Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.0.3 - Missing Authorization
Vulnerability Versions up to 4.0.3 4.0.4 CVSS 5.3
CVE-2025-14061
Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR...
Vulnerability Versions up to 4.0.7 4.0.8 CVSS 5.3
CVE-2025-66133
Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.0.7 - Missing Authorization
Vulnerability Versions up to 4.0.7 4.0.8 CVSS 5.3
CVE-2024-3599
WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) <= 3.0.2 - Missing Authorization to...
Vulnerability Versions up to 3.0.2 3.1.0 CVSS 5.3
CVE-2025-66075
Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.0.3 - Missing Authorization
Vulnerability Versions up to 4.0.3 4.0.4 CVSS 4.3
CVE-2025-11754 High 4.1.3
CVE-2025-11754 Cookie Banner for GDPR / CCPA – WPLP Cookie Consent Sensitive Information Exposure

Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Consent <= 4.1.2 - Missing Authorization to Sensitive Information Exposure

CVE-2024-4869 High 3.3.0
CVE-2024-4869 Cookie Banner for GDPR / CCPA – WPLP Cookie Consent Stored Cross-Site Scripting

WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) <= 3.2.0 - Unauthenticated Stored Cross-Site Scripting via Client-IP header

CVE-2023-23678 Medium 2.2.6
CVE-2023-23678 Cookie Banner for GDPR / CCPA – WPLP Cookie Consent Vulnerability

WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 2.2.5 - Authenticated(Administrator+) CSV Injection

CVE-2025-66080 Medium 4.0.4
CVE-2025-66080 Cookie Banner for GDPR / CCPA – WPLP Cookie Consent Vulnerability

Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.0.3 - Missing Authorization

CVE-2025-14061 Medium 4.0.8
CVE-2025-14061 Cookie Banner for GDPR / CCPA – WPLP Cookie Consent Vulnerability

Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Consent <= 4.0.7 - Missing Authorization to Unauthenticated Arbitrary Post Deletion

CVE-2025-66133 Medium 4.0.8
CVE-2025-66133 Cookie Banner for GDPR / CCPA – WPLP Cookie Consent Vulnerability

Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.0.7 - Missing Authorization

CVE-2024-3599 Medium 3.1.0
CVE-2024-3599 Cookie Banner for GDPR / CCPA – WPLP Cookie Consent Vulnerability

WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) <= 3.0.2 - Missing Authorization to Unauthenticated Arbitrary Post Deletion

CVE-2025-66075 Medium 4.0.4
CVE-2025-66075 Cookie Banner for GDPR / CCPA – WPLP Cookie Consent Vulnerability

Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.0.3 - Missing Authorization

Coverage Snapshot

What this page helps you verify fast

This hub clusters tracked records for Cookie Banner for GDPR / CCPA – WPLP Cookie Consent so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
10 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
0 critical and 2 high severity findings.
Recent CVEs
CVE-2025-11754, CVE-2025-66080 and CVE-2025-14061
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

CVE-2025-11754 High Patch path listed

CVE-2025-11754: Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Consent <= 4.1.2 - Missing Authorization to Sensitive Information Exposure

The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'gdpr/v1/settings' REST API endpoint in all versions up to,...

Published
Feb 18, 2026
Patch Status
4.1.3
CVE-2025-14061 Medium Patch path listed

CVE-2025-14061: Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Consent <= 4.0.7 - Missing Authorization to Unauthenticated Arbitrary Post Deletion

The Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Consent plugin for WordPress is vulnerable to unauthorized data modific...

Published
Dec 16, 2025
Patch Status
4.0.8
Known Vulnerabilities

Reports for Cookie Banner for GDPR / CCPA – WPLP Cookie Consent

Sorted by latest disclosure date so newly published issues surface first.

Plugin High Patched: Yes CVE-2025-11754
CVE-2025-11754: Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Consent <= 4.1.2 - Missing Authorization to Sensitive Information Exposure

The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'gdpr/v1/settings' REST API endpoint in all versions up to, and including, 4.1.2. This makes it possible for unauthenticated attackers to retrieve se...

Published
Feb 18, 2026
Patched Release
4.1.3
Affected Versions
Versions up to 4.1.2
Next Step
Update to 4.1.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-66080
CVE-2025-66080: Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.0.3 - Missing Authorization

The Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpl_data_req_process_delete() function in versions up to, and including, 4.0.3. This makes it possible for unauthen...

Published
Dec 30, 2025
Patched Release
4.0.4
Affected Versions
Versions up to 4.0.3
Next Step
Update to 4.0.4 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-14061
CVE-2025-14061: Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Consent <= 4.0.7 - Missing Authorization to Unauthenticated Arbitrary Post Deletion

The Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Consent plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the gdpr_delete_policy_data function in all ver...

Published
Dec 16, 2025
Patched Release
4.0.8
Affected Versions
Versions up to 4.0.7
Next Step
Update to 4.0.8 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-66133
CVE-2025-66133: Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.0.7 - Missing Authorization

The Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Consent plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.0.7. Th...

Published
Dec 15, 2025
Patched Release
4.0.8
Affected Versions
Versions up to 4.0.7
Next Step
Update to 4.0.8 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-66075
CVE-2025-66075: Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.0.3 - Missing Authorization

The Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Consent plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.0.3. Th...

Published
Nov 08, 2025
Patched Release
4.0.4
Affected Versions
Versions up to 4.0.3
Next Step
Update to 4.0.4 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-49285
CVE-2025-49285: WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 3.8.0 - Cross-Site Request Forgery

The Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.0. This is due to missing or incorrect nonce v...

Published
Jun 05, 2025
Patched Release
3.8.1
Affected Versions
Versions up to 3.8.0
Next Step
Update to 3.8.1 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-11724
CVE-2024-11724: Cookie Consent for WP – Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) <= 3.6.5 - Missing Authorization to Authenticated (Subscriber+) Whitelist Script

The Cookie Consent for WP – Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpl_script_save AJAX action in all versions up to,...

Published
Dec 11, 2024
Patched Release
3.6.6
Affected Versions
Versions up to 3.6.5
Next Step
Update to 3.6.6 or newer if supported.
Plugin High Patched: Yes CVE-2024-4869
CVE-2024-4869: WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) <= 3.2.0 - Unauthenticated Stored Cross-Site Scripting via Client-IP header

The WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Client-IP’ header in all versions up to, and including, 3.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unau...

Published
Jun 25, 2024
Patched Release
3.3.0
Affected Versions
Versions up to 3.2.0
Next Step
Update to 3.3.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-3599
CVE-2024-3599: WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) <= 3.0.2 - Missing Authorization to Unauthenticated Arbitrary Post Deletion

The WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the gdpr_policy_process_delete() function in all versions up to, and including, 3.0.2. This makes it possible for unauthenticat...

Published
Apr 16, 2024
Patched Release
3.1.0
Affected Versions
Versions up to 3.0.2
Next Step
Update to 3.1.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-23678
CVE-2023-23678: WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 2.2.5 - Authenticated(Administrator+) CSV Injection

The WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 2.2.5. This allows authenticated administrators to embed untrusted input into exported CSV files, which can result in code execution when t...

Published
Jun 20, 2023
Patched Release
2.2.6
Affected Versions
Versions up to 2.2.5
Next Step
Update to 2.2.6 or newer if supported.