PLUGIN SECURITY

Is Cookie Notice safe?

Consent management platform for WordPress — GDPR, CCPA & ePrivacy cookie consent, autoblocking, consent records, Google Consent Mode v2 & GPC.

What this plugin does

  • Slug: cookie-notice
  • Author: Humanityco
  • 900000+ active installs
  • 96/100 rating (3024 reviews on wordpress.org)
  • 41631738 all-time downloads
  • On WordPress.org since 2013-07-08

CCPAconsentcookiesGDPRprivacy

Maintenance status

  • Latest known version: 3.1.4
  • Last updated: 2026-08-20 11:04am GMT
  • Tested up to WordPress: 7.0.4
  • Requires PHP: 7.4+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

6 known CVEs on file for Cookie Notice. Reported between 2021 and 2025.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-11186 Cookie Compliance for WordPress – Cookie Consent, GDPR & CCPA [cookie-notice] < 2.5.9 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 2.5.9 2.5.9 2025-11-21 ✓ fixed in latest
CVE-2025-67554 Cookie Compliance for WordPress – Cookie Consent, GDPR & CCPA [cookie-notice] < 2.5.9 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.9 < 2.5.9 2.5.9 2025-10-21 ✓ fixed in latest
CVE-2022-3399 Cookie Compliance for WordPress – Cookie Consent, GDPR & CCPA [cookie-notice] < 2.4.18 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.4 < 2.4.18 2.4.18 2024-08-15 ✓ fixed in latest
CVE-2023-0823 Cookie Compliance for WordPress – Cookie Consent, GDPR & CCPA [cookie-notice] < 2.4.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.4.7 2.4.7 2023-03-06 ✓ fixed in latest
CVE-2023-24400 Cookie Compliance for WordPress – Cookie Consent, GDPR & CCPA [cookie-notice] < 2.4.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 2.4.7 2.4.7 2023-03-02 ✓ fixed in latest
CVE-2021-24569 Cookie Compliance for WordPress – Cookie Consent, GDPR & CCPA [cookie-notice] < 2.1.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 2.1.4 2.1.4 2021-08-30 ✓ fixed in latest

How to fix it

Keep Cookie Notice updated — 3.1.4 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.