Vulnerabilities
Summary — last 7 days
New vulnerabilities2,739▲ 32 vs. last week
Critical / high1,474▲ 364 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)62▼ 464 vs. last week
8 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (6.4) | 0.33% | — | WP Gdpr Cookie ConsentAI | 6/9/2026 | 7/23/2026 | The WP GDPR Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ninja_gdpr_ajax_actions' AJAX action in versions up to, and including, 1.0.0. This is due to missing capability and nonce checks on the handleAjaxCalls() function, combined with insufficient input sanitization on the… | |
| Deferred | High (7.1) | 0.12% | — | Shahjahan Jewel WP Gdpr Cookie ConsentAI | 11/6/2025 | 6/17/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Shahjahan Jewel WP GDPR Cookie Consent wp-gdpr-cookie-consent allows Stored XSS.This issue affects WP GDPR Cookie Consent: from n/a through <= 1.0.0. | |
| Deferred | Medium (5.4) | 0.26% | — | Cookieinformation WP Gdpr ComplianceAI | 4/26/2024 | 6/17/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Cookie Information A/S WP GDPR Compliance.This issue affects WP GDPR Compliance: from n/a through 2.0.23. | |
| Modified | High (8.8) | 1.5% | — | Cookieinformation Wp-gdpr-compliance | 2/5/2024 | 6/17/2026 | The Cookie Information | Free GDPR Consent Solution plugin for WordPress is vulnerable to arbitrary option updates due to a missing capability check on its AJAX request handler in versions up to, and including, 2.0.22. This makes it possible for authenticated attackers, with subscriber-level access or higher, to edit… | |
| Modified | Medium (6.5) | 0.85% | — | Appsaloon WP Gdpr | 6/7/2023 | 6/17/2026 | The WP GDPR plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in versions up to, and including, 2.1.1. This makes it possible for unauthenticated attackers to delete any comment and modify the plugin’s settings. | |
| Modified | Medium (6.1) | 1.6% | — | Cookieinformation Wp-gdpr-compliance | 3/14/2022 | 6/17/2026 | The Cookie Information | Free GDPR Consent Solution WordPress plugin before 2.0.8 does not escape user data before outputting it back in attributes in the admin dashboard, leading to a Reflected Cross-Site Scripting issue | |
| Modified | Medium (6.1) | 0.94% | — | Appsaloon Wp-gdpr | 8/31/2020 | 6/17/2026 | controller/controller-comments.php in WP GDPR plugin through 2.1.1 has unauthenticated stored XSS. | |
| Modified | Critical (9.8) | 88% | — | Van-ons Wp-gdpr-compliance | 11/12/2018 | 6/17/2026 | The Van Ons WP GDPR Compliance (aka wp-gdpr-compliance) plugin before 1.4.3 for WordPress allows remote attackers to execute arbitrary code because $wpdb->prepare() input is mishandled, as exploited in the wild in November 2018. |