Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3
Critical0
High0
Medium3
Reset
Showing 1-3 of 3 records
Threat Entry Updated 2025-10-27

CVE-2025-12136 - Eprivacy Cookie Consent Plugin

The Real Cookie Banner: GDPR & ePrivacy Cookie Consent plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.2.4. This is due to insufficient validation on the user-supplied URL in the '/scanner/scan-without-login' REST API endpoint. This makes it possible for authenticated attackers, with administrator-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services via the `url` parameter.

PLUGIN Eprivacy Cookie Consent

CVE-2025-12136

MEDIUM CVSS 6.8 2025-10-24
Threat Entry Updated 2025-06-09

CVE-2025-1485 - Eprivacy Cookie Consent Plugin

The Real Cookie Banner: GDPR & ePrivacy Cookie Consent WordPress plugin before 5.1.6, real-cookie-banner-pro WordPress plugin before 5.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

PLUGIN Eprivacy Cookie Consent

CVE-2025-1485

MEDIUM CVSS 4.8 2025-06-02
Threat Entry Updated 2024-11-21

CVE-2022-0445 - Eprivacy Cookie Consent Plugin

The WordPress Real Cookie Banner: GDPR (DSGVO) & ePrivacy Cookie Consent WordPress plugin before 2.14.2 does not have CSRF checks in place when resetting its settings, allowing attackers to make a logged in admin reset them via a CSRF attack

PLUGIN Eprivacy Cookie Consent

CVE-2022-0445

MEDIUM CVSS 6.5 2022-03-07
Scroll to top