Really-simple-plugins
Really-simple-plugins Complianz: vulnerabilidades y CVE
Really-simple-plugins Complianz tiene 12 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE12
Últimos 12 meses5
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-65498 | Media (5.3) | 0.33% | — | 23 jul 2026 | Unauthenticated Sensitive Data Exposure in Complianz <= 7.5.0 versions. |
| CVE-2026-65497 | Alta (7.2) | 0.54% | — | 23 jul 2026 | Administrator PHP Object Injection in Complianz <= 7.5.0 versions. |
| CVE-2026-65496 | Media (4.4) | 0.21% | — | 23 jul 2026 | Author Server Side Request Forgery (SSRF) in Complianz <= 7.5.0 versions. |
| CVE-2026-4019 | Media (5.3) | 0.44% | — | 29 abr 2026 | The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to unauthorized data access in all versions up to, and including, 7.4.5 This is due to the REST API endpoint at… |
| CVE-2025-11185 | Media (6.4) | 0.26% | — | 18 feb 2026 | The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cmplz-accept-link shortcode in all versions up to, and including, 7.4.3 due to insufficient… |
| CVE-2024-1592 | Media (4.3) | 0.20% | — | 2 mar 2024 | The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.5.6. This is due to missing or incorrect nonce validation on the… |
| CVE-2023-6498 | Media (4.8) | 0.32% | — | 4 ene 2024 | The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to and including 6.5.5 due to insufficient input sanitization and output… |
| CVE-2023-34030 | Alta (8.8) | 0.34% | — | 30 nov 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Really Simple Plugins Complianz, Really Simple Plugins Complianz Premium allows Cross-Site Request Forgery.This issue affects Complianz: from n/a through 6.4.5;… |
| CVE-2023-33333 | Alta (8.8) | 0.31% | — | 30 nov 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Really Simple Plugins Complianz, Really Simple Plugins Complianz Premium allows Cross-Site Scripting (XSS).This issue affects Complianz: from n/a through 6.4.4;… |
| CVE-2023-1069 | Media (5.4) | 0.56% | — | 27 mar 2023 | The Complianz WordPress plugin before 6.4.2, Complianz Premium WordPress plugin before 6.4.2 do not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is… |
| CVE-2022-3494 | Alta (8.8) | 1.3% | — | 7 nov 2022 | The Complianz WordPress plugin before 6.3.4, and Complianz Premium WordPress plugin before 6.3.6 allow a translators to inject arbitrary SQL through an unsanitized translation. SQL can be injected through an infected… |
| CVE-2022-0193 | Media (6.1) | 0.88% | — | 14 feb 2022 | The Complianz WordPress plugin before 6.0.0 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting |