Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total4
Critical0
High1
Medium3
Reset
Showing 1-4 of 4 records
Threat Entry Updated 2025-12-18

CVE-2025-14061 - Wp Cookie Consent Plugin

The Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Consent plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the gdpr_delete_policy_data function in all versions up to, and including, 4.0.7. This makes it possible for unauthenticated attackers to permanently delete arbitrary posts, pages, attachments, and other post types by ID.

PLUGIN Wp Cookie Consent

CVE-2025-14061

MEDIUM CVSS 5.3 2025-12-17
Threat Entry Updated 2025-07-14

CVE-2024-11724 - Wp Cookie Consent Plugin

The Cookie Consent for WP – Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpl_script_save AJAX action in all versions up to, and including, 3.6.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to whitelist scripts.

PLUGIN Wp Cookie Consent

CVE-2024-11724

MEDIUM CVSS 4.3 2024-12-12
Threat Entry Updated 2025-07-09

CVE-2024-4869 - Wp Cookie Consent Plugin

The WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Client-IP’ header in all versions up to, and including, 3.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wp Cookie Consent

CVE-2024-4869

HIGH CVSS 7.2 2024-06-26
Threat Entry Updated 2025-07-10

CVE-2024-3599 - Wp Cookie Consent Plugin

The WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the gdpr_policy_process_delete() function in all versions up to, and including, 3.0.2. This makes it possible for unauthenticated attackers to delete arbitrary posts.

PLUGIN Wp Cookie Consent

CVE-2024-3599

MEDIUM CVSS 5.3 2024-05-02
Scroll to top