WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in GDPR Cookie Compliance – Cookie Banner, Cookie Consent, Cookie Notice for CCPA, EU Cookie Law

Cookie notice banner for GDPR, CCPA, EU cookie law, data protection and privacy regulations and other cookie law and consent notice requirements on yo …

10Reported vulnerabilities
6.5Highest CVSS score
5.1.0Latest version
300,000+Active installs

What to do now

Update GDPR Cookie Compliance – Cookie Banner, Cookie Consent, Cookie Notice for CCPA, EU Cookie Law to 5.1.0 or later. 10 of these have a fixed version available. Updating resolves them.

Plugin last updated: July 21, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2023-4013 Medium 6.5 0.3% Before 4.12.5 4.12.5 August 30, 2023
CVE-2025-1621 Medium 4.8 0.3% Before 4.15.7 4.15.7 March 16, 2025
CVE-2025-1620 Medium 4.8 0.3% Before 4.15.7 4.15.7 March 16, 2025
CVE-2025-1619 Medium 4.8 0.3% Before 4.15.7 4.15.7 March 16, 2025
CVE-2025-2205 Medium 4.8 0.4% Before 4.15.7 4.15.7 March 12, 2025
CVE-2019-25143 Medium 4.3 0.7% Before 4.0.3 4.0.3 June 7, 2023
CVE-2025-1624 Low 3.5 0.3% Before 4.15.9 4.15.9 March 16, 2025
CVE-2025-1623 Low 3.5 0.3% Before 4.15.9 4.15.9 March 16, 2025
CVE-2026-16613 Medium 4.3 0.1% 5.0.0 and earlier 5.1.0 July 27, 2026
CVE-2025-1622 Low 3.5 0.2% Before 4.15.7 4.15.7 March 16, 2025

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.