Vulnerabilities

Summary — last 7 days

New vulnerabilities2,739▲ 32 vs. last week
Critical / high1,474▲ 364 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)62▼ 464 vs. last week
–

8 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredMedium (6.4)0.33%—WP Gdpr Cookie ConsentAI6/9/20267/23/2026
The WP GDPR Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ninja_gdpr_ajax_actions' AJAX action in versions up to, and including, 1.0.0. This is due to missing capability and nonce checks on the handleAjaxCalls() function, combined with insufficient input sanitization on the…
DeferredHigh (7.1)0.12%—Shahjahan Jewel WP Gdpr Cookie ConsentAI11/6/20256/17/2026
Cross-Site Request Forgery (CSRF) vulnerability in Shahjahan Jewel WP GDPR Cookie Consent wp-gdpr-cookie-consent allows Stored XSS.This issue affects WP GDPR Cookie Consent: from n/a through <= 1.0.0.
DeferredMedium (5.4)0.26%—Cookieinformation WP Gdpr ComplianceAI4/26/20246/17/2026
Cross-Site Request Forgery (CSRF) vulnerability in Cookie Information A/S WP GDPR Compliance.This issue affects WP GDPR Compliance: from n/a through 2.0.23.
ModifiedHigh (8.8)1.5%—Cookieinformation Wp-gdpr-compliance2/5/20246/17/2026
The Cookie Information | Free GDPR Consent Solution plugin for WordPress is vulnerable to arbitrary option updates due to a missing capability check on its AJAX request handler in versions up to, and including, 2.0.22. This makes it possible for authenticated attackers, with subscriber-level access or higher, to edit…
ModifiedMedium (6.5)0.85%—Appsaloon WP Gdpr6/7/20236/17/2026
The WP GDPR plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in versions up to, and including, 2.1.1. This makes it possible for unauthenticated attackers to delete any comment and modify the plugin’s settings.
ModifiedMedium (6.1)1.6%—Cookieinformation Wp-gdpr-compliance3/14/20226/17/2026
The Cookie Information | Free GDPR Consent Solution WordPress plugin before 2.0.8 does not escape user data before outputting it back in attributes in the admin dashboard, leading to a Reflected Cross-Site Scripting issue
ModifiedMedium (6.1)0.94%—Appsaloon Wp-gdpr8/31/20206/17/2026
controller/controller-comments.php in WP GDPR plugin through 2.1.1 has unauthenticated stored XSS.
ModifiedCritical (9.8)88%—Van-ons Wp-gdpr-compliance11/12/20186/17/2026
The Van Ons WP GDPR Compliance (aka wp-gdpr-compliance) plugin before 1.4.3 for WordPress allows remote attackers to execute arbitrary code because $wpdb->prepare() input is mishandled, as exploited in the wild in November 2018.