cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forwp-gdpr-cookie-consent wp-gdpr-cookie-consent

Direction: descending
Jun 10, 2026

WP GDPR Cookie Consent # CVE-2026-8977

CVE, Research URL

CVE-2026-8977

Date
Jun 09, 2026
Research Description
The WP GDPR Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ninja_gdpr_ajax_actions' AJAX action in versions up to, and including, 1.0.0. This is due to missing capability and nonce checks on the handleAjaxCalls() function, combined with insufficient input sanitization on the gdprConfig values and missing output escaping in the generateCSS() function which echoes stored configuration values directly into a <style> block rendered on wp_head. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 1.0.0.
Status
vulnerable
Jul 02, 2025

WP GDPR Cookie Consent # CVE-2025-53316

CVE, Research URL

CVE-2025-53316

Date
Nov 06, 2025
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in Shahjahan Jewel WP GDPR Cookie Consent wp-gdpr-cookie-consent allows Stored XSS.This issue affects WP GDPR Cookie Consent: from n/a through <= 1.0.0.
Affected versions
max 1.0.0.
Status
vulnerable