CVE · Medium

CVE-2026-16613 — GDPR Cookie Compliance – Cookie Banner, Cookie Consent, Cookie Notice for CCPA, EU Cookie Law [gdpr-cookie-compliance] < 5.1.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-16613 GDPR Cookie Compliance – Cookie Banner, Cookie Consent, Cookie Notice for CCPA, EU Cookie Law [gdpr-cookie-compliance] < 5.1.0 Cross-Site Request Forgery (CSRF) Medium 4.3 < 5.1.0 5.1.0 2026-07-27

CVE-2026-16613

A vulnerability in the GDPR Cookie Compliance WordPress plugin prior to version 5.1.0 allowed unauthorized access to certain functionality, enabling an attacker to induce cookie expiration for any visitor through a specially designed URL. This exploit bypassed authentication requirements and lacked origin verification, effectively allowing malicious activity such as user logout and site-wide cookie deletion.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.