Extension WordPress
Vulnérabilités WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode
Cette page rassemble les failles publiées pour WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode
14 fiches
Cookie Banner for GDPR / CCPA <= 4.3.6 – Authenticated (Administrator+) SQL Injection via 'scan_id' Parameter
The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to generic SQL Injection via the 'scan_id' parameter in all versions up to, and including, 4.3.6 due to insufficient escaping on the…
*-4.3.6
4.3.7
09/07/2026
Cookie Banner for GDPR / CCPA <= 4.3.6 – Missing Authorization to Authenticated (Subscriber+) Scan Schedule Modification via gcc_save_schedule_scan AJAX Action
The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the gdpr_cookie_consent_ajax_save_schedule_scan() function (the wp_ajax_gcc_save_schedule_scan AJAX action) in versions up to, and including,…
*-4.3.6
4.3.7
09/07/2026
Cookie Banner for GDPR / CCPA <= 4.3.5 – Authenticated (Administrator+) SQL Injection via 's' Parameter
The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, and including, 4.3.5 due to insufficient escaping on the…
*-4.3.5
4.3.6
02/07/2026
Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Consent <= 4.1.2 – Missing Authorization to Sensitive Information Exposure
The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'gdpr/v1/settings' REST API endpoint in all versions up to, and including, 4.1.2. This makes it possible…
*-4.1.2
4.1.3
18/02/2026
Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.0.3 – Missing Authorization
The Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpl_data_req_process_delete() function in versions up to, and including, 4.0.3. This makes…
*-4.0.3
4.0.4
30/12/2025
Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Consent <= 4.0.7 – Missing Authorization to Unauthenticated Arbitrary Post Deletion
The Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Consent plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the gdpr_delete_policy_data…
*-4.0.7
4.0.8
16/12/2025
Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.0.7 – Missing Authorization
The Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Consent plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in…
*-4.0.7
4.0.8
15/12/2025
Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.0.3 – Missing Authorization
The Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Consent plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in…
*-4.0.3
4.0.4
08/11/2025
WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 3.8.0 – Cross-Site Request Forgery
The Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.0. This…
*-3.8.0
3.8.1
05/06/2025
Cookie Consent for WP – Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) <= 3.6.5 – Missing Authorization to Authenticated (Subscriber+) Whitelist Script
The Cookie Consent for WP – Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpl_script_save…
*-3.6.5
3.6.6
11/12/2024
WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) <= 3.2.0 – Unauthenticated Stored Cross-Site Scripting via Client-IP header
The WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Client-IP’ header in all versions up to, and including, 3.2.0 due to insufficient input sanitization and…
*-3.2.0
3.3.0
25/06/2024
WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) <= 3.0.2 – Missing Authorization to Unauthenticated Arbitrary Post Deletion
The WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the gdpr_policy_process_delete() function in all versions up to, and including,…
*-3.0.2
3.1.0
16/04/2024
WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 2.2.5 – Authenticated(Administrator+) CSV Injection
The WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 2.2.5. This allows authenticated administrators to embed untrusted input into exported CSV files, which…
*-2.2.5
2.2.6
20/06/2023
Freemius SDK <= 2.4.2 – Missing Authorization Checks
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions…
[*, 2.1.1)
2.1.1
04/03/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.