CVE · Medium

CVE-2026-4019 — Complianz GDPR/CCPA Cookie Consent Banner [complianz-gdpr] < 7.4.6

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-4019 Complianz GDPR/CCPA Cookie Consent Banner [complianz-gdpr] < 7.4.6 Missing Authorization Medium 5.3 < 7.4.6 7.4.6 2026-04-28

CVE-2026-4019

The Complianz plugin's REST API endpoint is open to unauthorized access due to a flawed permission check in all versions up to 7.4.5. Specifically, the cmplz_rest_consented_content function retrieves post data without verifying whether it's publicly accessible or if the user has viewing privileges. As a result, attackers can read sensitive block content from private posts.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.