Vulnerabilities and security researches forwp-gdpr-cookie-consent wp-gdpr-cookie-consent
Direction: descendingJun 10, 2026
WP GDPR Cookie Consent # CVE-2026-8977
- CVE, Research URL
- Home page URL
- Application
- Date
- Jun 09, 2026
- Research Description
- The WP GDPR Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ninja_gdpr_ajax_actions' AJAX action in versions up to, and including, 1.0.0. This is due to missing capability and nonce checks on the handleAjaxCalls() function, combined with insufficient input sanitization on the gdprConfig values and missing output escaping in the generateCSS() function which echoes stored configuration values directly into a <style> block rendered on wp_head. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
max 1.0.0.
- Status
-
vulnerable
Jul 02, 2025
WP GDPR Cookie Consent # CVE-2025-53316
- CVE, Research URL
- Home page URL
- Application
- Date
- Nov 06, 2025
- Research Description
- Cross-Site Request Forgery (CSRF) vulnerability in Shahjahan Jewel WP GDPR Cookie Consent wp-gdpr-cookie-consent allows Stored XSS.This issue affects WP GDPR Cookie Consent: from n/a through <= 1.0.0.
- Affected versions
-
max 1.0.0.
- Status
-
vulnerable