{"error":0,"message":null,"data":{"name":"Cookiebot by Usercentrics &#8211; Automatic Cookie Banner for GDPR\/CCPA &amp; Google Consent Mode","plugin":"cookiebot","link":"https:\/\/wordpress.org\/plugins\/cookiebot\/","latest":"1789387020","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"898f46b6906453b8d8e3d05db30207c50f62d59bbc55fd3ece5db8a0cf3ee09d","name":"Cookiebot by Usercentrics &#8211; Automatic Cookie Banner for GDPR\/CCPA &amp; Google Consent Mode [cookiebot] < 3.6.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.6.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"6082e79a28c37bc70662b5ec82c1fb8eccc2fbc4","name":"WordPress Cookiebot plugin <= 3.6.0 - Reflected Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/cookiebot\/vulnerability\/wordpress-cookiebot-plugin-3-6-0-reflected-cross-site-scripting-xss-vulnerability","description":"Reflected Cross-Site Scripting (XSS) vulnerability found by Antony Garand (Sucuri) in WordPress Cookiebot plugin (versions <= 3.6.0).","date":"2020-09-09"}],"impact":[]},{"uuid":"32f2fcbbc3e8198ee812f04752f0c7844bfaa7393cff4586b90ecf0c8c5da7e6","name":"Cookiebot by Usercentrics &#8211; Automatic Cookie Banner for GDPR\/CCPA &amp; Google Consent Mode [cookiebot] < 3.6.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.6.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"eee83ed7-aded-40a2-9c13-86aca0a748ae","name":"Cookiebot &lt; 3.6.1 - CSRF &amp; XSS","link":"https:\/\/wpscan.com\/vulnerability\/eee83ed7-aded-40a2-9c13-86aca0a748ae","description":"Antony Garand of Sucuri discovered that multiple WordPress plugins were vulnerable to Cross-Site Scripting (XSS) within the admin panel, which could be exploited by using s Cross-Site Request Forgery (CSRF) attack.","date":null}],"impact":[]},{"uuid":"0004bfb61cacbffba63589e9bcb26bb7a12c787b6774a12c24c49e73501ef57b","name":"Cookiebot by Usercentrics &#8211; Automatic Cookie Banner for GDPR\/CCPA &amp; Google Consent Mode [cookiebot] < 3.6.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.6.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"8cdd58f8-39a4-4c00-a2a7-fa12ded9a822","name":"Cookiebot &lt; 3.6.1 - Authenticated Reflected Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/8cdd58f8-39a4-4c00-a2a7-fa12ded9a822","description":"Versions prior to 3.6.1 are susceptible to this attack, which allows hackers to exploit the vulnerability found on administrative pages.","date":null}],"impact":[]},{"uuid":"ea5e41390cb6ca0eee37253e7e3729751ed3a0cfd4caff7134a3d73ad4634b65","name":"Cookiebot by Usercentrics &#8211; Automatic Cookie Banner for GDPR\/CCPA &amp; Google Consent Mode [cookiebot] < 3.6.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.6.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"3bb59d641f9c4144e272965c1dc4d2f9a93e4ce6","name":"Cookiebot | GDPR\/CCPA Compliant Cookie Consent and Control <=  3.6.0 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/cookiebot\/cookiebot-gdprccpa-compliant-cookie-consent-and-control-360-reflected-cross-site-scripting","description":"The Cookiebot | GDPR\/CCPA Compliant Cookie Consent and Control plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the tab parameter in versions up to, and including 3.6.0 This makes it possible for unauthenticated attackers to inject arbitrary web scripts in administrative pages that execute if they can successfully trick a site administrator into performing an action such as clicking on a link.","date":"2020-09-08"}],"impact":[]},{"uuid":"5db1c5d48e9643c6f49ffe2bd31dc22f3ca5fe8e77aad651de83553e350c84c9","name":"Cookiebot by Usercentrics &#8211; Automatic Cookie Banner for GDPR\/CCPA &amp; Google Consent Mode [cookiebot] < 4.4.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.4.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-1666","name":"Cookie banner plugin for WordPress \u2013 Cookiebot CMP by Usercentrics <= 4.4.1 - Missing Authorization to Authenticated (Subscriber+) Survey Submission","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-1666","description":"The Cookie banner plugin for WordPress \u2013 Cookiebot CMP by Usercentrics plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the send_uninstall_survey() function in all versions up to, and including, 4.4.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to submit the uninstall survey on behalf of a website.","date":"0000-00-00"},{"id":"13f03a08733af9c66c51f73f932dc97816363308","name":"WordPress Cookiebot Plugin <= 4.4.1 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/cookiebot\/vulnerability\/wordpress-cookiebot-plugin-4-4-1-missing-authorization-to-authenticated-subscriber-survey-submission-vulnerability","description":"<p>WordPress Cookiebot Plugin <= 4.4.1 is vulnerable to Broken Access Control<\/p><p>Software: Cookiebot<\/p><p>Fixed in version 4.4.2 <\/p><p>Affected Version <= 4.4.1<\/p><p>CVE: CVE-2025-1666<\/p>","date":"2025-03-06"},{"id":"2b01733f56153a7550fde3a4ac3f5f14162e3170","name":"Cookie banner plugin for WordPress \u2013 Cookiebot CMP by Usercentrics <= 4.4.1 - Missing Authorization to Authenticated (Subscriber+) Survey Submission","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/cookiebot\/cookie-banner-plugin-for-wordpress-cookiebot-cmp-by-usercentrics-441-missing-authorization-to-authenticated-subscriber-survey-submission","description":"The Cookie banner plugin for WordPress \u2013 Cookiebot CMP by Usercentrics plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the send_uninstall_survey() function in all versions up to, and including, 4.4.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to submit the uninstall survey on behalf of a website.","date":"2025-03-05"},{"id":"EUVD-2025-6106","name":"EUVD-2025-6106","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-6106","description":"The Cookie banner plugin for WordPress \u2013 Cookiebot CMP by Usercentrics plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the send_uninstall_survey() function in all versions up to, and including, 4.4.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to submit the uninstall survey on behalf of a website.","date":"2025-03-06"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.001"}},{"uuid":"1d278d46a1a7021ba272bb2e4dbb7349460a168d6792d3d3cb4bffa6bb6495df","name":"Cookiebot by Usercentrics &#8211; Automatic Cookie Banner for GDPR\/CCPA &amp; Google Consent Mode [cookiebot] < 4.5.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.5.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-53197","name":"CVE-2025-53197","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-53197","description":"[en] Cross-Site Request Forgery (CSRF) vulnerability in cookiebot Cookiebot allows Cross Site Request Forgery. This issue affects Cookiebot: from n\/a through 4.5.8.","date":"2025-06-27"},{"id":"605feb2c4c6c1546742c1c46e3c7f55ddb8779d5","name":"Cookiebot <= 4.5.8 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/cookiebot\/cookiebot-458-cross-site-request-forgery","description":"The Usercentrics Cookiebot \u2013 Automatic Cookie Banner for GDPR\/CCPA & Google Consent Mode plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5.8. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2025-06-27"},{"id":"EUVD-2025-19334","name":"EUVD-2025-19334","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-19334","description":"Cross-Site Request Forgery (CSRF) vulnerability in cookiebot Cookiebot allows Cross Site Request Forgery. This issue affects Cookiebot: from n\/a through 4.5.8.","date":"2025-06-27"}],"impact":{"cvss":{"version":null,"vector":null,"av":null,"ac":null,"pr":null,"ui":null,"s":null,"c":null,"i":null,"a":null,"score":"0.0","severity":null,"exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"none","exploitable":null,"impact":null}}},{"uuid":"1707cf86311b36a140553ca4561e8be5bc6812ed877d73169c341401e5ae8593","name":"Cookiebot by Usercentrics &#8211; Automatic Cookie Banner for GDPR\/CCPA &amp; Google Consent Mode [cookiebot] < 4.6.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.6.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-25407","name":"CVE-2026-25407","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-25407","description":"[en] Missing Authorization vulnerability in cookiebot Cookiebot cookiebot allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cookiebot: from n\/a through <= 4.6.4.","date":"2026-02-19"},{"id":"70100960e0a29bb3308d746022bce794d829a0bb","name":"Cookiebot by Usercentrics \u2013 Automatic Cookie Banner for GDPR\/CCPA & Google Consent Mode <= 4.6.4 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/cookiebot\/cookiebot-by-usercentrics-automatic-cookie-banner-for-gdprccpa-google-consent-mode-464-missing-authorization","description":"The Cookiebot by Usercentrics \u2013 Automatic Cookie Banner for GDPR\/CCPA & Google Consent Mode plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.6.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.","date":"2026-01-29"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1776413536"}