Extension WordPress

Vulnérabilités WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode

Cette page rassemble les failles publiées pour WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode, leurs plages de versions affectées et les correctifs signalés dans la base locale.

14Vulnérabilités
0Critiques
14Avec correctif
7,5CVSS maximal

Historique de sécurité

CVE et vulnérabilités de WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode

14 fiches

CVE-2026-14475 Moyenne · 4,9
WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode

Cookie Banner for GDPR / CCPA <= 4.3.6 – Authenticated (Administrator+) SQL Injection via 'scan_id' Parameter

The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to generic SQL Injection via the 'scan_id' parameter in all versions up to, and including, 4.3.6 due to insufficient escaping on the…

Versions affectées

*-4.3.6

Correctif

4.3.7

Publication

09/07/2026

CVE-2026-12955 Moyenne · 4,3
WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode

Cookie Banner for GDPR / CCPA <= 4.3.6 – Missing Authorization to Authenticated (Subscriber+) Scan Schedule Modification via gcc_save_schedule_scan AJAX Action

The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the gdpr_cookie_consent_ajax_save_schedule_scan() function (the wp_ajax_gcc_save_schedule_scan AJAX action) in versions up to, and including,…

Versions affectées

*-4.3.6

Correctif

4.3.7

Publication

09/07/2026

CVE-2026-12920 Moyenne · 4,9
WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode

Cookie Banner for GDPR / CCPA <= 4.3.5 – Authenticated (Administrator+) SQL Injection via 's' Parameter

The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, and including, 4.3.5 due to insufficient escaping on the…

Versions affectées

*-4.3.5

Correctif

4.3.6

Publication

02/07/2026

CVE-2025-11754 Élevée · 7,5
WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode

Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Consent <= 4.1.2 – Missing Authorization to Sensitive Information Exposure

The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'gdpr/v1/settings' REST API endpoint in all versions up to, and including, 4.1.2. This makes it possible…

Versions affectées

*-4.1.2

Correctif

4.1.3

Publication

18/02/2026

CVE-2025-66080 Moyenne · 5,3
WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode

Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.0.3 – Missing Authorization

The Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpl_data_req_process_delete() function in versions up to, and including, 4.0.3. This makes…

Versions affectées

*-4.0.3

Correctif

4.0.4

Publication

30/12/2025

CVE-2025-14061 Moyenne · 5,3
WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode

Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Consent <= 4.0.7 – Missing Authorization to Unauthenticated Arbitrary Post Deletion

The Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Consent plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the gdpr_delete_policy_data…

Versions affectées

*-4.0.7

Correctif

4.0.8

Publication

16/12/2025

CVE-2025-66133 Moyenne · 5,3
WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode

Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.0.7 – Missing Authorization

The Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Consent plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in…

Versions affectées

*-4.0.7

Correctif

4.0.8

Publication

15/12/2025

CVE-2025-66075 Moyenne · 4,3
WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode

Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.0.3 – Missing Authorization

The Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Consent plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in…

Versions affectées

*-4.0.3

Correctif

4.0.4

Publication

08/11/2025

CVE-2025-49285 Moyenne · 4,3
WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode

WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 3.8.0 – Cross-Site Request Forgery

The Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.0. This…

Versions affectées

*-3.8.0

Correctif

3.8.1

Publication

05/06/2025

CVE-2024-11724 Moyenne · 4,3
WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode

Cookie Consent for WP – Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) <= 3.6.5 – Missing Authorization to Authenticated (Subscriber+) Whitelist Script

The Cookie Consent for WP – Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpl_script_save…

Versions affectées

*-3.6.5

Correctif

3.6.6

Publication

11/12/2024

CVE-2024-4869 Élevée · 7,2
WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode

WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) <= 3.2.0 – Unauthenticated Stored Cross-Site Scripting via Client-IP header

The WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Client-IP’ header in all versions up to, and including, 3.2.0 due to insufficient input sanitization and…

Versions affectées

*-3.2.0

Correctif

3.3.0

Publication

25/06/2024

CVE-2024-3599 Moyenne · 5,3
WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode

WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) <= 3.0.2 – Missing Authorization to Unauthenticated Arbitrary Post Deletion

The WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the gdpr_policy_process_delete() function in all versions up to, and including,…

Versions affectées

*-3.0.2

Correctif

3.1.0

Publication

16/04/2024

CVE-2023-23678 Moyenne · 6,4
WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode

WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 2.2.5 – Authenticated(Administrator+) CSV Injection

The WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 2.2.5. This allows authenticated administrators to embed untrusted input into exported CSV files, which…

Versions affectées

*-2.2.5

Correctif

2.2.6

Publication

20/06/2023

CVE-2022-4974 Moyenne · 6,3
WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode

Freemius SDK <= 2.4.2 – Missing Authorization Checks

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions…

Versions affectées

[*, 2.1.1)

Correctif

2.1.1

Publication

04/03/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités