PLUGIN SECURITY
Is Complianz Gdpr safe?
Publish your cookie banner or notice in minutes. Automatically scan cookies, and create policies to align with GDPR, CCPA, and Google Consent Mode.
What this plugin does
- Slug:
complianz-gdpr - Author: Complianz
- 1000000+ active installs
- 94/100 rating (1655 reviews on wordpress.org)
- 31940051 all-time downloads
- On WordPress.org since 2018-06-26
CCPAcookie bannercookie consentcookie noticeGDPR
Maintenance status
- Latest known version: 7.5.2
- Last updated: 2026-08-18 6:49am GMT
- Tested up to WordPress: 7.0.4
- Requires PHP: 7.4+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
12 known CVEs on file for Complianz Gdpr.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-65498 | Complianz GDPR/CCPA Cookie Consent Banner [complianz-gdpr] <= 7.5.1 (unfixed) | Exposure of Sensitive System Information to an Unauthorized Control Sphere | Medium 5.3 | < 7.5.1 | 7.5.1 | 2026-07-22 | ✓ fixed in latest |
| CVE-2026-4019 | Complianz GDPR/CCPA Cookie Consent Banner [complianz-gdpr] < 7.4.6 | Missing Authorization | Medium 5.3 | < 7.4.6 | 7.4.6 | 2026-04-28 | ✓ fixed in latest |
| CVE-2025-11185 | Complianz GDPR/CCPA Cookie Consent Banner [complianz-gdpr] < 7.4.4 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 7.4.4 | 7.4.4 | 2026-02-17 | ✓ fixed in latest |
| CVE-2024-1592 | Complianz GDPR/CCPA Cookie Consent Banner [complianz-gdpr] < 7.0.0 | Cross-Site Request Forgery (CSRF) | Medium 4.3 | < 7.0.0 | 7.0.0 | 2024-03-01 | ✓ fixed in latest |
| CVE-2023-6498 | Complianz GDPR/CCPA Cookie Consent Banner [complianz-gdpr] < 6.5.6 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.8 | < 6.5.6 | 6.5.6 | 2024-01-03 | ✓ fixed in latest |
| CVE-2023-33333 | Complianz GDPR/CCPA Cookie Consent Banner [complianz-gdpr] < 6.4.5 | Cross-Site Request Forgery (CSRF) | High 7.1 | < 6.4.5 | 6.4.5 | 2023-05-12 | ✓ fixed in latest |
| — | Complianz GDPR/CCPA Cookie Consent Banner [complianz-gdpr] < 6.4.5 | — | Unknown | < 6.4.5 | 6.4.5 | 2023-05-12 | ✓ fixed in latest |
| — | Complianz GDPR/CCPA Cookie Consent Banner [complianz-gdpr] < 6.4.5 | — | Unknown | < 6.4.5 | 6.4.5 | 2023-05-12 | ✓ fixed in latest |
+ 9 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2023-1069 | Complianz GDPR/CCPA Cookie Consent Banner [complianz-gdpr] < 6.4.2 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 6.4.2 | 6.4.2 | 2023-03-06 | ✓ fixed in latest |
| CVE-2022-3494 | Complianz GDPR/CCPA Cookie Consent Banner [complianz-gdpr] < 6.3.4 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 8.8 | < 6.3.4 | 6.3.4 | 2022-10-17 | ✓ fixed in latest |
| CVE-2022-0193 | Complianz GDPR/CCPA Cookie Consent Banner [complianz-gdpr] < 6.0.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 6.0.0 | 6.0.0 | 2022-01-17 | ✓ fixed in latest |
| — | Complianz GDPR/CCPA Cookie Consent Banner [complianz-gdpr] < 7.4.5 | — | Unknown | < 7.4.5 | 7.4.5 | 0000-00-00 | ✓ fixed in latest |
| — | Complianz GDPR/CCPA Cookie Consent Banner [complianz-gdpr] <= 7.5.1 (unfixed) | — | Unknown | < 7.5.1 | 7.5.1 | 0000-00-00 | ✓ fixed in latest |
| — | Complianz GDPR/CCPA Cookie Consent Banner [complianz-gdpr] <= 7.5.1 (unfixed) | — | Unknown | < 7.5.1 | 7.5.1 | 0000-00-00 | ✓ fixed in latest |
| CVE-2026-2389 | Complianz – GDPR/CCPA Cookie Consent < 7.4.5 - Contributor+ Stored XSS via Content Filter | — | Unknown | < 7.4.5 | 7.4.5 | — | ✓ fixed in latest |
| CVE-2026-65497 | Complianz – GDPR/CCPA Cookie Consent < 7.5.2 - Admin+ PHP Object Injection | — | Unknown | < 7.5.2 | 7.5.2 | — | ✓ fixed in latest |
| CVE-2026-65496 | Complianz – GDPR/CCPA Cookie Consent <= 7.5.1 - Author+ Server-Side Request Forgery | — | Unknown | not specified | no fix on file | — | — |
How to fix it
Keep Complianz Gdpr updated — 7.5.2 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
1 of the vulnerabilities above has no fixed version on file — there's no update that resolves it. Consider deactivating this plugin or switching to one of the alternatives below.
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- CookieYes – Cookie Banner for Cookie Consent (Easy to setup GDPR/CCPA Compliant Cookie Notice) — 1000000+ active installs — 96/100 (3228) — max PHP 8.4
- Cookie Compliance for WordPress – Cookie Consent, GDPR & CCPA — 900000+ active installs — 96/100 (3024) — max PHP 8.4
- GDPR Cookie Compliance – Cookie Banner, Cookie Consent, Cookie Notice for CCPA, EU Cookie Law — 300000+ active installs — 92/100 (205) — max PHP 8.4
- iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more — 200000+ active installs — 94/100 (396) — max PHP 8.4
- WPConsent – Cookie Banner & Cookie Consent for Privacy Compliance (GDPR / CCPA / EU Compliance Cookie Notice) — 200000+ active installs — 98/100 (78)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.