cleantalk
Vulnerabilities and Security Researches

Complianz – GDPR/CCPA Cookie Consent, PSC-2026-64617

PSC, Research URL

PSC-2026-64617

Published on
Feb 25, 2026
Research Description
Cookie consent and privacy-compliance plugins are deceptively security-sensitive because they sit at the intersection of front-end script execution, visitor consent state, and site-wide configuration. They often manage banner templates, block or release third-party scripts, generate legal documents, and store consent-related settings and logs — which means weaknesses can translate into stored/reflected XSS in banners or documents, CSRF-driven configuration changes (silently altering consent behavior), data leakage via misprotected endpoints, or integrity issues in the rules that decide when scripts are allowed to run. Complianz – GDPR/CCPA Cookie Consent version 7.4.4.2 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64617, confirming that the plugin was reviewed from a secure code perspective with attention to the most common exploitation paths for privacy, cookie, and consent-management plugins.
Affected versions
Min 7.4.4.2, max 7.4.4.2.
Status
SAFE & CERTIFIED