{"error":0,"message":null,"data":{"name":"Complianz GDPR\/CCPA Cookie Consent Banner","plugin":"complianz-gdpr","link":"https:\/\/wordpress.org\/plugins\/complianz-gdpr\/","latest":"1788872580","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"535f19e951e32b0e8928d82a695cd8c03cdd293cd86e067f26768c260a1a0668","name":"Complianz GDPR\/CCPA Cookie Consent Banner [complianz-gdpr] < 6.0.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.0.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-0193","name":"CVE-2022-0193","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-0193","description":"[en] The Complianz WordPress plugin before 6.0.0 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting","date":"2022-02-14"},{"id":"2687311b228f2c96f8f5a6773cba77229a74a7d4","name":"WordPress Complianz \u2013 GDPR\/CCPA Cookie Consent plugin <= 5.5.2 - Reflected Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/complianz-gdpr\/vulnerability\/wordpress-complianz-gdpr-ccpa-cookie-consent-plugin-5-5-2-reflected-cross-site-scripting-xss-vulnerability","description":"Reflected Cross-Site Scripting (XSS) vulnerability discovered by Krzysztof Zaj\u0105c in WordPress Complianz \u2013 GDPR\/CCPA Cookie Consent plugin (versions <= 5.5.2).","date":"2022-01-17"},{"id":"30d1d328-9f19-4c4c-b90a-04937d617864","name":"One more step","link":"https:\/\/wpscan.com\/vulnerability\/30d1d328-9f19-4c4c-b90a-04937d617864","description":null,"date":null},{"id":"b1dd0e1409510e377d89fc8838d0993ccec95c80","name":"Complianz - GDPR\/CCPA Cookie Consent <= 5.5.2 - Reflected Cross-Site Scripting via s parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/complianz-gdpr\/complianz-gdprccpa-cookie-consent-552-reflected-cross-site-scripting-via-s-parameter","description":"The Complianz WordPress plugin before 6.0.0 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting","date":"2022-01-17"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"f49f0e78e3f98a451ab77950d5be39bedfb0759ad55e8646c7ca8f05a940f36b","name":"Complianz GDPR\/CCPA Cookie Consent Banner [complianz-gdpr] < 6.3.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.3.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-3494","name":"CVE-2022-3494","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-3494","description":"[en] The Complianz WordPress plugin before 6.3.4, and Complianz Premium WordPress plugin before 6.3.6 allow a translators to inject arbitrary SQL through an unsanitized translation. SQL can be injected through an infected translation file, or by a user with a translator role through translation plugins such as Loco Translate or WPML.","date":"2022-11-07"},{"id":"5485db29883ee4c4e086d560765311efedf22c83","name":"WordPress Complianz plugin <= 6.3.3 - Auth. SQL Injection (SQLi) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/complianz-gdpr\/vulnerability\/wordpress-complianz-plugin-6-3-3-auth-sql-injection-sqli-vulnerability","description":"Auth. SQL Injection (SQLi) vulnerability discovered by Sakri Rafael Koskimies (saggre) in the WordPress Complianz plugin (versions <= 6.3.3).\nUpdate the WordPress Complianz \u2013 GDPR\/CCPA Cookie Consent plugin to the latest available version (at least 6.3.4).","date":"2022-10-17"},{"id":"1aaa57361ad1d4e147f8b79cfef7d4298472f35d","name":"Complianz Free <= 6.3.3 & Premium <= 6.3.5  - SQL Injection via Translations","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/detail\/complianz-free-633-premium-635-sql-injection-via-translations","description":"The Complianz plugin for WordPress is vulnerable to SQL Injection via unescaped translations in versions up to, and including, 6.3.3 (Free) and 6.3.5 (Premium) due to insufficient escaping on the user supplied translation (either from a translation file or a user with translator role through a translation plugin) and lack of sufficient preparation on the existing SQL query. This makes it possible for attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2022-10-17"},{"id":"71db75c0-5907-4237-884f-8db88b1a9b34","name":"Complianz (Free &lt; 6.3.4, Premium &lt; 6.3.6) - Translator SQLi","link":"https:\/\/wpscan.com\/vulnerability\/71db75c0-5907-4237-884f-8db88b1a9b34","description":"The plugins allow a translators to inject arbitrary SQL through an unsanitized translation. SQL can be injected through an infected translation file, or by a user with a translator role through translation plugins such as Loco Translate or WPML.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"dad22ba5be54a500ad1aa48c173c5a93bded2a1e57e29548750070cbb3848e67","name":"Complianz GDPR\/CCPA Cookie Consent Banner [complianz-gdpr] < 6.4.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.4.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-1069","name":"CVE-2023-1069","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-1069","description":"[en] The Complianz WordPress plugin before 6.4.2, Complianz Premium WordPress plugin before 6.4.2 do not validate and escape some of its shortcode attributes before outputting them back in a page\/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks","date":"2023-03-27"},{"id":"9fd1eb16fb019768da13e9938840a64e98b63fe2","name":"Complianz - GDPR\/CCPA Cookie Consent <= 6.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/complianz-gdpr\/complianz-gdprccpa-cookie-consent-641-authenticated-contributor-stored-cross-site-scripting","description":"The Complianz - GDPR\/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in versions up to, and including, 6.4.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2023-03-06"},{"id":"1ed539af56460a2e90f403d074bb51c7258595f7","name":"WordPress  Complianz \u2013 GDPR\/CCPA Cookie Consent Plugin  < 6.4.2 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/complianz-gdpr\/vulnerability\/wordpress-complianz-gdpr-ccpa-cookie-consent-plugin-6-4-2-contributor-stored-xss-vulnerability","description":"Update the WordPress Complianz \u2013 GDPR\/CCPA Cookie Consent plugin to the latest available version (at least 6.4.2).\nErwan LR (WPScan) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Complianz \u2013 GDPR\/CCPA Cookie Consent Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 6.4.2.","date":"2023-03-08"},{"id":"ca60427508da5cc72a26d527f051aca8f495abea","name":"WordPress  Complianz Premium Plugin  < 6.4.2 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/complianz-gdpr-premium\/vulnerability\/wordpress-complianz-gdpr-ccpa-cookie-consent-plugin-6-4-2-contributor-stored-xss-vulnerability-2","description":"Update the WordPress Complianz Premium plugin to the latest available version (at least 6.4.2).\nErwan LR (WPScan) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Complianz Premium Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 6.4.2.","date":"2023-03-28"},{"id":"caacc50c-822e-46e9-bc0b-681349fd0dda","name":"Complianz - GDPR\/CCPA Cookie Consent &lt; 6.4.2 - Contributor+ Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/caacc50c-822e-46e9-bc0b-681349fd0dda","description":"The plugins do not validate and escape some of its shortcode attributes before outputting them back in a page\/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"f761ae7e0c93446eb3817089e1cc67335bb8b2ce836fa7462a3f77a8541e6176","name":"Complianz GDPR\/CCPA Cookie Consent Banner [complianz-gdpr] < 6.4.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.4.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"d273c78eed23b3c508c37e20fc9764aab6b4a853","name":"Complianz - GDPR\/CCPA Cookie Consent <= 6.4.4 - Cross-Site Request Forgery via maybe_install_suggested_plugins","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/complianz-gdpr\/complianz-gdprccpa-cookie-consent-644-cross-site-request-forgery-via-maybe-install-suggested-plugins","description":"The Complianz - GDPR\/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.4.4. This is due to missing or incorrect nonce validation on the maybe_install_suggested_plugins function. This makes it possible for unauthenticated attackers to install suggested plugins via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2023-05-12"},{"id":"CVE-2023-33333","name":"CVE-2023-33333","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-33333","description":"[en] Cross-Site Request Forgery (CSRF) vulnerability in Really Simple Plugins Complianz, Really Simple Plugins Complianz Premium allows Cross-Site Scripting (XSS).This issue affects Complianz: from n\/a through 6.4.4; Complianz Premium: from n\/a through 6.4.6.1.","date":"2023-11-30"},{"id":"e226e3af74fb98f0148f2e4c5a8dd08d0e957e03","name":"WordPress  Complianz \u2013 GDPR\/CCPA Cookie Consent Plugin  <= 6.4.4 is vulnerable to Cross Site Request Forgery (CSRF)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/complianz-gdpr\/vulnerability\/wordpress-complianz-plugin-6-4-4-csrf-lead-to-site-wide-cross-site-scripting-xss-vulnerability","description":"Update the WordPress Complianz \u2013 GDPR\/CCPA Cookie Consent plugin to the latest available version (at least 6.4.5).\nRafie Muhammad (Patchstack) discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Complianz \u2013 GDPR\/CCPA Cookie Consent Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has been fixed in version 6.4.5.","date":"2023-06-20"},{"id":"b205d2316f605115d87f3762472d1440b4d92faf","name":"WordPress  Complianz Premium Plugin  <= 6.4.6.1 is vulnerable to Cross Site Request Forgery (CSRF)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/complianz-gdpr-premium\/vulnerability\/wordpress-complianz-premium-plugin-6-4-6-1-csrf-to-site-wide-cross-site-scripting-xss-vulnerability","description":"Update the WordPress Complianz Premium plugin to the latest available version (at least 6.4.7).\nRafie Muhammad (Patchstack) discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Complianz Premium Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has been fixed in version 6.4.7.","date":"2023-06-20"},{"id":"29a773f47956a72be514091ae229117892a7613e","name":"Complianz <= 6.4.4 (Premium <= 6.4.6.1)  - Cross-Site Request Forgery to Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/detail\/complianz-premium-6461-cross-site-request-forgery","description":"The Complianz plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting in versions up to, and including, 6.4.4 (Free) and 6.4.6.1 (Premium). This is due to missing nonce validation on the ajax_script_add() and ajax_script_save() functions called via AJAX actions. This makes it possible for unauthenticated attackers to invoke this function and add web scripts to a site via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2023-06-21"},{"id":"ad79844ad1296cc2c51bd1cddbf9714426b2406d","name":"Complianz - GDPR\/CCPA Cookie Consent <= 6.4.4 - Cross-Site Request Forgery via run_sync","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/complianz-gdpr\/complianz-gdprccpa-cookie-consent-644-cross-site-request-forgery-via-run-sync","description":"The Complianz - GDPR\/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.4.4. This is due to missing or incorrect nonce validation on the run_sync function. This makes it possible for unauthenticated attackers to sync cookies and serivces via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2023-05-12"},{"id":"f954500c1867db41f71bb80e0c079ab9304aeb55","name":"Complianz - GDPR\/CCPA Cookie Consent <= 6.4.4 - Cross-Site Request Forgery via ajax_edit_item","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/complianz-gdpr\/complianz-gdprccpa-cookie-consent-644-cross-site-request-forgery-via-ajax-edit-item","description":"The Complianz - GDPR\/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.4.4. This is due to missing or incorrect nonce validation on the ajax_edit_item function. This makes it possible for unauthenticated attackers to edit items via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2023-05-12"},{"id":"ed09143e8d0bc0bf6ac3ae4d894a36c8e63ee022","name":"Complianz - GDPR\/CCPA Cookie Consent <= 6.4.4 - Cross-Site Request Forgery via ajax_create_pages","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/complianz-gdpr\/complianz-gdprccpa-cookie-consent-644-cross-site-request-forgery-via-ajax-create-pages","description":"The Complianz - GDPR\/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.4.4. This is due to missing or incorrect nonce validation on the ajax_create_pages function. This makes it possible for unauthenticated attackers to create pages via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2023-05-12"},{"id":"49534719a6f10109fd321e9fd065cf5ff085278e","name":"Complianz - GDPR\/CCPA Cookie Consent <= 6.4.4 - Cross-Site Request Forgery via ajax_delete_snapshot","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/complianz-gdpr\/complianz-gdprccpa-cookie-consent-644-cross-site-request-forgery-via-ajax-delete-snapshot","description":"The Complianz - GDPR\/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.4.4. This is due to missing or incorrect nonce validation on the ajax_delete_snapshot function. This makes it possible for unauthenticated attackers to delete arbitrary files in the complianz 'snapshots' folder via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2023-05-12"},{"id":"5d8ccec9e7834cfd68fb0739706fef2e3082bc24","name":"Complianz - GDPR\/CCPA Cookie Consent <= 6.4.4 - Cross-Site Request Forgery via ajax_script_add","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/complianz-gdpr\/complianz-gdprccpa-cookie-consent-644-cross-site-request-forgery-via-ajax-script-add","description":"The Complianz - GDPR\/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.4.4. This is due to missing or incorrect nonce validation on the ajax_script_add function. This makes it possible for unauthenticated attackers to add scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2023-05-12"},{"id":"2477d216067a54530bc3a43ab469d48087e601c3","name":"Complianz - GDPR\/CCPA Cookie Consent <= 6.4.4 - Cross-Site Request Forgery via ajax_script_save","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/complianz-gdpr\/complianz-gdprccpa-cookie-consent-644-cross-site-request-forgery-via-ajax-script-save","description":"The Complianz - GDPR\/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.4.4. This is due to missing or incorrect nonce validation on the ajax_script_save function. This makes it possible for unauthenticated attackers to save scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2023-05-12"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"7.1","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"7.1","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"9584db320c1565ae52cb8787b931984b1ea8f4b218d31d05731fe40e48314c0a","name":"Complianz GDPR\/CCPA Cookie Consent Banner [complianz-gdpr] < 6.4.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.4.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"582a98cabb044d87c659bf28064c894eae502b9f","name":"Complianz - GDPR\/CCPA Cookie Consent <= 6.4.4 - Cross-Site Request Forgery via cmplz_duplicate_cookiebanner","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/complianz-gdpr\/complianz-gdprccpa-cookie-consent-644-cross-site-request-forgery-via-cmplz-duplicate-cookiebanner","description":"The Complianz - GDPR\/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.4.4. This is due to missing or incorrect nonce validation on the cmplz_duplicate_cookiebanner function. This makes it possible for unauthenticated attackers to duplicate the compliance cookie banner via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2023-05-12"}],"impact":[]},{"uuid":"5c4e3240efed37d921bcd9b7f5ab683118fe90e503b10081ece63437105f1bab","name":"Complianz GDPR\/CCPA Cookie Consent Banner [complianz-gdpr] < 6.4.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.4.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"13afb9c6cfde496383d82df48e4694ad88946e60","name":"Complianz - GDPR\/CCPA Cookie Consent <= 6.4.4 - Cross-Site Request Forgery via cmplz_delete_cookiebanner","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/complianz-gdpr\/complianz-gdprccpa-cookie-consent-644-cross-site-request-forgery-via-cmplz-delete-cookiebanner","description":"The Complianz - GDPR\/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.4.4. This is due to missing or incorrect nonce validation on the cmplz_delete_cookiebanner function. This makes it possible for unauthenticated attackers to delete the compliance cookie banner via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2023-05-12"}],"impact":[]},{"uuid":"cac3e4ca052b49dcdaa86afed39a41a5a99701fd2103d7998bf76f41ddf1f3cc","name":"Complianz GDPR\/CCPA Cookie Consent Banner [complianz-gdpr] < 6.5.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.5.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-6498","name":"CVE-2023-6498","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-6498","description":"[en] The Complianz \u2013 GDPR\/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to and including 6.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2024-01-04"},{"id":"c577148683c7e21a11c9d54cab36469c5648696b","name":"Complianz | GDPR\/CCPA Cookie Consent <= 6.5.5 - Authenticated(Administrator+) Stored Cross-site Scripting via settings","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/complianz-gdpr\/complianz-gdprccpa-cookie-consent-655-authenticatedadministrator-stored-cross-site-scripting-via-settings","description":"The Complianz \u2013 GDPR\/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to and including 6.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2024-01-03"},{"id":"6dc9e02d-bf1d-4358-bfb4-09120e256314","name":"Complianz | GDPR\/CCPA Cookie Consent &lt; 6.5.6 - Admin+ Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/6dc9e02d-bf1d-4358-bfb4-09120e256314","description":"The plugin does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"4.8","severity":"m","exploitable":"1.7","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"4.8","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"1.7","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"cd2bf91334e7f012e85a70c5e3a60e3dc1048aa8ad8d337940ae7cf9db34aebd","name":"Complianz GDPR\/CCPA Cookie Consent Banner [complianz-gdpr] < 7.0.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.0.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-1592","name":"CVE-2024-1592","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-1592","description":"[en] The Complianz \u2013 GDPR\/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.5.6. This is due to missing or incorrect nonce validation on the process_delete function in class-DNSMPD.php. This makes it possible for unauthenticated attackers to delete GDPR data requests via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2024-03-02"},{"id":"9dfffcdda687719f3e14a12bc11ad8adc7b0092a","name":"Complianz \u2013 GDPR\/CCPA Cookie Consent <= 6.5.6 - Cross-Site Request Forgery to Data Request Deletion","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/complianz-gdpr\/complianz-gdprccpa-cookie-consent-656-cross-site-request-forgery-to-data-request-deletion","description":"The Complianz \u2013 GDPR\/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.5.6. This is due to missing or incorrect nonce validation on the process_delete function in class-DNSMPD.php. This makes it possible for unauthenticated attackers to delete GDPR data requests via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2024-03-01"},{"id":"81acde31583bda02afaefd337830df28116f6907","name":"WordPress  Complianz \u2013 GDPR\/CCPA Cookie Consent Plugin    <= 6.5.6 is vulnerable to Cross Site Request Forgery (CSRF)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/complianz-gdpr\/vulnerability\/wordpress-complianz-gdpr-ccpa-cookie-consent-plugin-6-5-6-cross-site-request-forgery-to-data-request-deletion-vulnerability","description":"Update the WordPress Complianz \u2013 GDPR\/CCPA Cookie Consent plugin to the latest available version (at least 7.0.0).\nKrzysztof Zaj\u0105c discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Complianz \u2013 GDPR\/CCPA Cookie Consent Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has been fixed in version 7.0.0.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"0465732b-ae46-4791-bf5f-7a88fd98faad","name":"Complianz &ndash; GDPR\/CCPA Cookie Consent &lt; 7.0.0 - Cross-Site Request Forgery to Data Request Deletion","link":"https:\/\/wpscan.com\/vulnerability\/0465732b-ae46-4791-bf5f-7a88fd98faad","description":"The Complianz &ndash; GDPR\/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.5.6. This is due to missing or incorrect nonce validation on the process_delete function in class-DNSMPD.php. This makes it possible for unauthenticated attackers to delete GDPR data requests via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"3cd5623711672faa26cecfa72406988de96816f518017b3427337e72b7b2e734","name":"Complianz GDPR\/CCPA Cookie Consent Banner [complianz-gdpr] < 7.4.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.4.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-11185","name":"CVE-2025-11185","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-11185","description":"[en] The Complianz \u2013 GDPR\/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cmplz-accept-link shortcode in all versions up to, and including, 7.4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-02-18"},{"id":"d513d656e2cd99df7134fedbe998bfd1ce2f8cd3","name":"Complianz | GDPR\/CCPA Cookie Consent <= 7.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/complianz-gdpr\/complianz-gdprccpa-cookie-consent-743-authenticated-contributor-stored-cross-site-scripting-via-shortcode","description":"The Complianz \u2013 GDPR\/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cmplz-accept-link shortcode in all versions up to, and including, 7.4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-02-17"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"3.1","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"3.1","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"07e78ee1fafcd418b96611c4da3b56ec3d253294bbf9ec18f308a852b1dbba0f","name":"Complianz GDPR\/CCPA Cookie Consent Banner [complianz-gdpr] < 7.4.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.4.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-2389","name":"Complianz \u2013 GDPR\/CCPA Cookie Consent <= 7.4.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Content Filter","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-2389","description":"The Complianz \u2013 GDPR\/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 7.4.4.2. This is due to the `revert_divs_to_summary` function replacing `&#8221;` HTML entities with literal double-quote characters (`\"`) in post content without subsequent sanitization. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the injected page. The Classic Editor plugin is required to be installed and activated in order to exploit this vulnerability.","date":"0000-00-00"},{"id":"fe0f259ab26edd622af12f137e0c609a30213269","name":"Complianz \u2013 GDPR\/CCPA Cookie Consent <= 7.4.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Content Filter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/complianz-gdpr\/complianz-gdprccpa-cookie-consent-7442-authenticated-contributor-stored-cross-site-scripting-via-content-filter","description":"The Complianz \u2013 GDPR\/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 7.4.4.2. This is due to the `revert_divs_to_summary` function replacing `&#8221;` HTML entities with literal double-quote characters (`\"`) in post content without subsequent sanitization. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the injected page. The Classic Editor plugin is required to be installed and activated in order to exploit this vulnerability.","date":"2026-03-25"}],"impact":{"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"ef6c9e4b2de74e24f92471b4e6fa908270a5549af3ce729f4b636992f143e2a2","name":"Complianz GDPR\/CCPA Cookie Consent Banner [complianz-gdpr] < 7.4.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.4.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-4019","name":"CVE-2026-4019","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-4019","description":"[en] The Complianz \u2013 GDPR\/CCPA Cookie Consent plugin for WordPress is vulnerable to unauthorized data access in all versions up to, and including, 7.4.5 This is due to the REST API endpoint at \/wp-json\/complianz\/v1\/consent-area\/{post_id}\/{block_id} using __return_true as the permission_callback, allowing any unauthenticated user to access it. The cmplz_rest_consented_content() function retrieves a post by ID via get_post() and returns the consentedContent attribute of any complianz\/consent-area block found in it, without checking if the post is published or if the user has permission to read it. This makes it possible for unauthenticated attackers to read the consent area block content from private, draft, or unpublished posts.","date":"2026-04-29"},{"id":"c315499d904defecad690b22e64b4d2bb41b8a3b","name":"Complianz \u2013 GDPR\/CCPA Cookie Consent <= 7.4.5 - Missing Authorization to Unauthenticated Private Post Content Disclosure via Consent Area REST Endpoint","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/complianz-gdpr\/complianz-gdprccpa-cookie-consent-745-missing-authorization-to-unauthenticated-private-post-content-disclosure-via-consent-area-rest-endpoint","description":"The Complianz \u2013 GDPR\/CCPA Cookie Consent plugin for WordPress is vulnerable to unauthorized data access in all versions up to, and including, 7.4.5 This is due to the REST API endpoint at \/wp-json\/complianz\/v1\/consent-area\/{post_id}\/{block_id} using __return_true as the permission_callback, allowing any unauthenticated user to access it. The cmplz_rest_consented_content() function retrieves a post by ID via get_post() and returns the consentedContent attribute of any complianz\/consent-area block found in it, without checking if the post is published or if the user has permission to read it. This makes it possible for unauthenticated attackers to read the consent area block content from private, draft, or unpublished posts.","date":"2026-04-28"},{"id":"316a9eb871decc18771ce1bf0e214033d5be852b","name":"WordPress Complianz Plugin <= 7.4.5 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/complianz-gdpr\/vulnerability\/wordpress-complianz-gdpr-ccpa-cookie-consent-plugin-7-4-5-missing-authorization-to-unauthenticated-private-post-content-disclosure-vulnerability","description":"<p>WordPress Complianz Plugin <= 7.4.5 is vulnerable to Broken Access Control<\/p><p>Software: Complianz<\/p><p>Fixed in version 7.4.6 <\/p><p>Affected Version <= 7.4.5<\/p><p>CVE: CVE-2026-4019<\/p>","date":"2026-04-28"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"25cd61a54c175bcd416ac3b78833c2d8b083ec0f9dfbc69f6fb5c3363a6fddef","name":"Complianz GDPR\/CCPA Cookie Consent Banner [complianz-gdpr] <= 7.5.1 (unfixed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.5.1","max_operator":"le","unfixed":"1","closed":"0"},"source":[{"id":"CVE-2026-65497","name":"WordPress Complianz plugin <= 7.5.0 - PHP Object Injection vulnerability","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-65497","description":"Administrator PHP Object Injection in Complianz <= 7.5.0 versions.","date":"0000-00-00"},{"id":"8d6dda715debf6f17ca161ce3a8cc82e87da6c95","name":"Complianz \u2013 GDPR\/CCPA Cookie Consent <= 7.5.1 - Authenticated (Administrator+) PHP Object Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/complianz-gdpr\/complianz-gdprccpa-cookie-consent-751-authenticated-administrator-php-object-injection","description":"The Complianz \u2013 GDPR\/CCPA Cookie Consent plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 7.5.1 via deserialization of untrusted input. This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.","date":"2026-07-22"}],"impact":[]},{"uuid":"729b5c9e24ddc20ca8237c3ff371210b991ec3a9fd04979609f289a151e2dfc9","name":"Complianz GDPR\/CCPA Cookie Consent Banner [complianz-gdpr] <= 7.5.1 (unfixed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.5.1","max_operator":"le","unfixed":"1","closed":"0"},"source":[{"id":"CVE-2026-65498","name":"CVE-2026-65498","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-65498","description":"[en] Unauthenticated Sensitive Data Exposure in Complianz <= 7.5.0 versions.","date":"2026-07-23"},{"id":"29be05a3af4025bd865da7d1673e998be6e162d2","name":"Complianz \u2013 GDPR\/CCPA Cookie Consent <= 7.5.1 - Unauthenticated Information Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/complianz-gdpr\/complianz-gdprccpa-cookie-consent-751-unauthenticated-information-exposure","description":"The Complianz \u2013 GDPR\/CCPA Cookie Consent plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.5.1. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.","date":"2026-07-22"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-497","name":"Exposure of Sensitive System Information to an Unauthorized Control Sphere","description":"The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"979b5e984a3b9749bf44ca3c8be5e84d115055cd922face826e18083efb26198","name":"Complianz GDPR\/CCPA Cookie Consent Banner [complianz-gdpr] <= 7.5.1 (unfixed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.5.1","max_operator":"le","unfixed":"1","closed":"0"},"source":[{"id":"CVE-2026-65496","name":"WordPress Complianz plugin <= 7.5.0 - Server Side Request Forgery (SSRF) vulnerability","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-65496","description":"Author Server Side Request Forgery (SSRF) in Complianz <= 7.5.0 versions.","date":"0000-00-00"},{"id":"99111d1f7dfc6d664ef12936bfcd7e8036f79205","name":"Complianz \u2013 GDPR\/CCPA Cookie Consent <= 7.5.1 - Authenticated (Author+) Server-Side Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/complianz-gdpr\/complianz-gdprccpa-cookie-consent-751-authenticated-author-server-side-request-forgery","description":"The Complianz \u2013 GDPR\/CCPA Cookie Consent plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.5.1. This makes it possible for authenticated attackers, with Author-level access and above, to make web requests to arbitrary locations originating from the web application which can be used to query and modify information from internal services.","date":"2026-07-22"}],"impact":{"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"a59b25f4d48dc410983887902cfd94afd9023ac24c2616fe428460a4209726ee","name":"Complianz GDPR\/CCPA Cookie Consent Banner [complianz-gdpr] < 7.5.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.5.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-83561","name":"CVE-2026-83561","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-83561","description":"[en] The Complianz GDPR\/CCPA Cookie Consent Banner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via Elementor Cookie Blocker Regex in all versions up to, and including, 7.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires an administrator to approve the attacker's comment, and the site must have both the Elementor plugin installed and Complianz configured with the Twitter or Facebook cookie\/script blocker enabled.","date":"2026-09-18"},{"id":"0596d122a73e78f3065d0c9bb068b5bc04c17d2a","name":"Complianz GDPR\/CCPA Cookie Consent Banner <= 7.5.4 - Unauthenticated Stored Cross-Site Scripting via Elementor Cookie Blocker Regex","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/complianz-gdpr\/complianz-gdprccpa-cookie-consent-banner-754-unauthenticated-stored-cross-site-scripting-via-elementor-cookie-blocker-regex","description":"The Complianz GDPR\/CCPA Cookie Consent Banner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via Elementor Cookie Blocker Regex in all versions up to, and including, 7.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires an administrator to approve the attacker's comment, and the site must have both the Elementor plugin installed and Complianz configured with the Twitter or Facebook cookie\/script blocker enabled.","date":"2026-07-22"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"7.2","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"7.2","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1789709719"}