PLUGIN SECURITY
Is Cookie Notice safe?
Consent management platform for WordPress — GDPR, CCPA & ePrivacy cookie consent, autoblocking, consent records, Google Consent Mode v2 & GPC.
What this plugin does
- Slug:
cookie-notice - Author: Humanityco
- 900000+ active installs
- 96/100 rating (3024 reviews on wordpress.org)
- 41631738 all-time downloads
- On WordPress.org since 2013-07-08
CCPAconsentcookiesGDPRprivacy
Maintenance status
- Latest known version: 3.1.4
- Last updated: 2026-08-20 11:04am GMT
- Tested up to WordPress: 7.0.4
- Requires PHP: 7.4+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
6 known CVEs on file for Cookie Notice. Reported between 2021 and 2025.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2025-11186 | Cookie Compliance for WordPress – Cookie Consent, GDPR & CCPA [cookie-notice] < 2.5.9 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 2.5.9 | 2.5.9 | 2025-11-21 | ✓ fixed in latest |
| CVE-2025-67554 | Cookie Compliance for WordPress – Cookie Consent, GDPR & CCPA [cookie-notice] < 2.5.9 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.9 | < 2.5.9 | 2.5.9 | 2025-10-21 | ✓ fixed in latest |
| CVE-2022-3399 | Cookie Compliance for WordPress – Cookie Consent, GDPR & CCPA [cookie-notice] < 2.4.18 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.4 | < 2.4.18 | 2.4.18 | 2024-08-15 | ✓ fixed in latest |
| CVE-2023-0823 | Cookie Compliance for WordPress – Cookie Consent, GDPR & CCPA [cookie-notice] < 2.4.7 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 2.4.7 | 2.4.7 | 2023-03-06 | ✓ fixed in latest |
| CVE-2023-24400 | Cookie Compliance for WordPress – Cookie Consent, GDPR & CCPA [cookie-notice] < 2.4.7 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 2.4.7 | 2.4.7 | 2023-03-02 | ✓ fixed in latest |
| CVE-2021-24569 | Cookie Compliance for WordPress – Cookie Consent, GDPR & CCPA [cookie-notice] < 2.1.4 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 4.8 | < 2.1.4 | 2.1.4 | 2021-08-30 | ✓ fixed in latest |
How to fix it
Keep Cookie Notice updated — 3.1.4 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- CookieYes – Cookie Banner for Cookie Consent (Easy to setup GDPR/CCPA Compliant Cookie Notice) — 1000000+ active installs — 96/100 (3228) — max PHP 8.4
- Complianz GDPR/CCPA Cookie Consent Banner — 1000000+ active installs — 94/100 (1654) — max PHP 8.4
- CookieAdmin – Cookie Consent Banner — 400000+ active installs — 100/100 (4) — max PHP 8.4
- GDPR Cookie Compliance – Cookie Banner, Cookie Consent, Cookie Notice for CCPA, EU Cookie Law — 300000+ active installs — 92/100 (205) — max PHP 8.4
- iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more — 200000+ active installs — 94/100 (396) — max PHP 8.4
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.