Complianz GDPR/CCPA Cookie Consent Banner

Complianz GDPR/CCPA Cookie Consent Banner has 23 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2026; all 23 are fixed as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high. 2023 was the busiest year with 13 disclosures.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 13 of the records (57%). Other recurring categories include Cross-Site Scripting, Deserialization Of Untrusted Data.

Every one of the 23 issues recorded for Complianz GDPR/CCPA Cookie Consent Banner has a vendor fix available, so running the current release closes all known holes.

8 independent researchers contributed these findings, most of them (7) reported by Rafie Muhammad. Complianz GDPR/CCPA Cookie Consent Banner is installed on roughly 1,000,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

01234567891026.06.2018Today17.01.20226.1Complianz - GDPR/CCPA Cookie Consent <= 5.5.2 - Reflected Cross-Site Scripting via s parameter CVSS 6.1 · 17.01.202217.10.20228.8Complianz Free <= 6.3.3 & Premium <= 6.3.5 - SQL Injection via Translations CVSS 8.8 · 17.10.202206.03.20236.4Complianz - GDPR/CCPA Cookie Consent <= 6.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 06.03.202312.05.20234.3Complianz - GDPR/CCPA Cookie Consent <= 6.4.4 - Cross-Site Request Forgery via maybe_install_suggested_plugins CVSS 4.3 · 12.05.20234.3Complianz - GDPR/CCPA Cookie Consent <= 6.4.4 - Cross-Site Request Forgery via cmplz_delete_cookiebanner CVSS 4.3 · 12.05.20234.3Complianz - GDPR/CCPA Cookie Consent <= 6.4.4 - Cross-Site Request Forgery via cmplz_duplicate_cookiebanner CVSS 4.3 · 12.05.20234.3Complianz - GDPR/CCPA Cookie Consent <= 6.4.4 - Cross-Site Request Forgery via run_sync CVSS 4.3 · 12.05.20235.4Complianz - GDPR/CCPA Cookie Consent <= 6.4.4 - Cross-Site Request Forgery via ajax_delete_snapshot CVSS 5.4 · 12.05.20236.1Complianz - GDPR/CCPA Cookie Consent <= 6.4.4 - Cross-Site Request Forgery via ajax_script_add CVSS 6.1 · 12.05.20234.3Complianz - GDPR/CCPA Cookie Consent <= 6.4.4 - Cross-Site Request Forgery via ajax_edit_item CVSS 4.3 · 12.05.20234.3Complianz - GDPR/CCPA Cookie Consent <= 6.4.4 - Cross-Site Request Forgery via ajax_create_pages CVSS 4.3 · 12.05.20236.1Complianz - GDPR/CCPA Cookie Consent <= 6.4.4 - Cross-Site Request Forgery via ajax_script_save CVSS 6.1 · 12.05.202330.05.20234.3Complianz | GDPR/CCPA Cookie Consent <= 6.4.5 - Cross-Site Request Forgery CVSS 4.3 · 30.05.202320.06.20234.3Complianz <= 6.4.5 (Premium <= 6.4.7) - Cross-Site Request Forgery CVSS 4.3 · 20.06.202321.06.20236.1Complianz <= 6.4.4 (Premium <= 6.4.6.1) - Cross-Site Request Forgery to Stored Cross-Site Scripting CVSS 6.1 · 21.06.202303.01.20244.4Complianz | GDPR/CCPA Cookie Consent <= 6.5.5 - Authenticated(Administrator+) Stored Cross-site Scripting via settings CVSS 4.4 · 03.01.202401.03.20244.3Complianz – GDPR/CCPA Cookie Consent <= 6.5.6 - Cross-Site Request Forgery to Data Request Deletion CVSS 4.3 · 01.03.202417.02.20266.4Complianz | GDPR/CCPA Cookie Consent <= 7.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode CVSS 6.4 · 17.02.202625.03.20264.9Complianz – GDPR/CCPA Cookie Consent <= 7.4.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Content Filter CVSS 4.9 · 25.03.202628.04.20265.3Complianz – GDPR/CCPA Cookie Consent <= 7.4.5 - Missing Authorization to Unauthenticated Private Post Content Disclosure via Consent Area REST Endpoint CVSS 5.3 · 28.04.202622.07.20266.4Complianz – GDPR/CCPA Cookie Consent <= 7.5.1 - Authenticated (Author+) Server-Side Request Forgery CVSS 6.4 · 22.07.20266.6Complianz – GDPR/CCPA Cookie Consent <= 7.5.1 - Authenticated (Administrator+) PHP Object Injection CVSS 6.6 · 22.07.20265.3Complianz – GDPR/CCPA Cookie Consent <= 7.5.1 - Unauthenticated Information Exposure CVSS 5.3 · 22.07.2026

Strategic Overview

Avg CVSSMedium
5.3/ 10
Patch Coverage100%
Open

0

Fixed

23

Get automatic notifications for all Complianz GDPR/CCPA Cookie Consent Banner vulnerabilities before they are exploited.

Highest severity on recordCVSS 8.8CVE-2022-3494

Complianz Free <= 6.3.3 & Premium <= 6.3.5 - SQL Injection via Translations

Read the full analysis

Vulnerability Records

23 records
2026-07-22 00:00CVE-2026-65496
6.4
Medium
Ananda DhakalYes
2026-07-22 00:00CVE-2026-65497
6.6
Medium
Ananda DhakalYes
2026-07-22 00:00CVE-2026-65498
5.3
Medium
Ananda DhakalYes
2026-04-28 19:52CVE-2026-4019
5.3
Medium
Wesley van de KampYes
2026-03-25 00:00CVE-2026-2389
4.9
Medium
Muhammad Yudha - DJYes
2026-02-17 21:15CVE-2025-11185
6.4
Medium
Muhammad Yudha - DJYes
2024-03-01 00:00CVE-2024-1592
4.3
Medium
Krzysztof ZającYes
2024-01-03 00:00CVE-2023-6498
4.4
Medium
WebbernautYes
2023-06-21 00:00CVE-2023-33333
6.1
Medium
Rafie MuhammadYes
2023-06-20 00:00CVE-2023-34030
4.3
Medium
Rafie MuhammadYes
Showing 1–10 of 23 reports
Complianz GDPR/CCPA Cookie Consent Banner banner
Latestv7.5.5

Complianz GDPR/CCPA Cookie Consent Banner

Complianz

Author

Complianz

4.7(1,656)
94/100
Last Updated
2026-09-08 (5d ago)
Active Installs
1,000,000+
Downloads
33,175,014
Requires WP
5.9+
Requires PHP
7.4+
Tested up to
WP 7.1
Created
2018-06-26 (8y ago)

Complianz is a Google-certified CMP (Consent Management Platform) for automated cookie notice and consent management. Set up a fully customizable cookie banner, auto-scan your cookies, generate customized cookie policy, and align with GDPR, ePrivacy, DSGVO, TTDSG, LGPD (Brasil), POPIA, APA, RGPD, CCPA/CPRA, PIPEDA (Canada), and other privacy laws. Trusted by 1,000,000+ users across 15+ languages, 10+ years of WordPress experience. Wizard-based easy setup; no coding required. Why millions of websites choose Complianz Fast setup: The guided setup walks you through each step from start to finish. You won’t need any legal or coding knowledge to get started. Automatic cookie scan: Complianz scans your site and shows you exactly which cookies and scripts are active, so you’re not left guessing. Work with the tools you already use: Connect with tools like Google Tag Manager and Google Analytics. No need to rethink your existing setup. Transparent Plans: Complianz free or paid plans don’t have monthly page views or sessions limits, so you can focus on your traffic growth. Features Answer a few questions in the Wizard, scan your WordPress site, and in a few minutes, Complianz sets up your consent settings based on your setup and location. It automatically configures consent settings based on your plugins, services, and region. Consent Management Auto-Configuration Wizard: Automatically sets up your site based on wizard questions, website scan (up to 50 posts), and dedicated plugin integrations. Third-Party Cookie Blocking: Blocks cookies from Google Maps, Facebook, Instagram, AdSense, HubSpot, reCAPTCHA, Twitter, ActiveCampaign, and more. Automatic Plugin & Service Detection: Custom integrations for plugins, themes, and services are detected automatically. Blocks iFrames, like YouTube, Vimeo, Dailymotion embedded videos and Social iFrames e.g. Instagram, Facebook et al. Placeholder Support: Shows video stills and individual placeholders for each blocked iFrame or social service. Script Center: Control scripts, iFrames, and plugins per category or service, — with dependency functionality and placeholder management. Proof of Consent: Records user consent following GDPR data minimization guidelines for audit-ready compliance. Periodic Cookie Scan: Automatically scans for changes in cookies, plugins, and third-party services on your site. Auto-Detection: Detects whether your site requires a cookie banner based on your current setup. Analytics Anonymization: Automatically anonymizes personal data for integrated statistics tools when needed. Cookie Consent Notice Region-Specific Cookie Banner: Display a cookie consent banner tailored to the EU, UK, US, Australia, South Africa, Brazil, Canada, — or use one banner worldwide. Subregion Consent Rules: Configure consent per subregion, such as TTDSG/DSGVO for Germany, CNIL for France, or CCPA/CPRA/CTDPA for specific US states. Banner Templates: Choose from multiple layouts: Cookie Wall, Accept/Dismiss, Consent per Category, or Consent per Service. Banner Templates include: GDPR-friendly Cookie Wall – Accept/Dismiss – Consent per Category – Consent per Service Legislation-Based Dismiss Options: Enable dismiss on scroll, time on page, or both and automatically adapt based on your applicable privacy law. Custom CSS & Templates: Fully customizable cookie banner design with your own CSS and templates. WCAG 2.1 AA & ADA Compliant: Cookie banners and legal documents designed following accessibility best practices. No jQuery Dependency: Fast and lightweight. No jQuery required. Privacy Laws & Guidelines Global Privacy Law Support: Ready for GDPR, ePrivacy, LGPD, DSGVO, CNIL, PECR, UK GDPR, UK DPA, CCPA, CPRA, COPPA, PIPEDA, CASL, POPIA, Australian Privacy Act, and the Brazilian General Data Protection Law. Regulation Differentiation: Distinguish between overlapping laws — GDPR vs. DSGVO/CNIL, CCPA vs. DNSMPI, or NRS 603A — based on your visitors’ location. Continuously Updated: Closely follows the latest developments in ePrivacy regulation, cookie law proposals, and global privacy legislation. Legal Documents Cookie Policy Generator: Generate a Cookie Policy with an easy wizard, drafted by an IT law firm. Do Not Sell My Personal Information: DNSMPI Page for CCPA/CPRA – if required. (Now called Opt-out Preferences.) Terms and Conditions are available in a separate plugin: Complianz – Terms and Conditions 250+ Service & Plugin Integrations Cookie Database Integration: Cookie Database Integration: Prefills cookie data from cookiedatabase.org, provides clear, transparent descriptions, and keeps everything continuously updated. WordPress Privacy Features: Export and erase personal data directly from your WordPress dashboard. Analytics & Tag Manager Support: Built-in support for Google Tag Manager, Google Analytics, Matomo, Matomo Tag Manager, Clicky, Yandex, Jetpack, and Burst Statistics. Cookie Categorization: Categorize cookies using Tag Manager or the built-in Script Center. Integration with the WP Consent API WP Consent API: Full integration with the WP Consent API for consent state sharing across plugins. Plugin Compatibility: Works with Gutenberg, Elementor, Divi, WPBakery, WooCommerce, Gravity Forms, WPForms, Contact Form 7, MonsterInsights, Forminator, HappyForms, Easy Digital Downloads, WP Google Maps, CAOS, and many more. Theme & Page Builder Tested: Tested with popular WordPress themes and page builders. Gutenberg Blocks: Includes native Gutenberg Blocks for easy content integration. Support Get help through the WordPress.org forum. You can check the documentation or browse existing threads or open a new one if you need more support. Share a clear description of your issue and the team will get back to you as soon as possible. Useful Links Support Forum Github MU Plugins Documentation Developer’s Guide Legal Definitions Translate Complianz Premium Features Go beyond the basics with the full website scan, advanced tools for legal documents, and premium support. Cookie Consent Notice Improve conversion with A/B testing: Test different cookie banners and measure which ones lead to higher consent rates. Consent Management Records of Consent: Keep records of your consent management changes and user’s consent registration. Integrates with Proof of Consent. Respects the Do Not Track settings and Global Privacy Controls in end-users’ browsers. Geo IP Cookie Consent: Display the correct Cookie notice based on IP location, but only if a banner is needed. Google Consent Mode: Use Consent Mode by Google with Google Tag Manager or Google Analytics to optimize ad performance with compliance. No further set-up needed. Integration with TCF v2.0: An IAB Europe Consent Framework for publishers. Registered CMP ID: 332 Data Request Forms and Registration Privacy Laws & Guidelines Simultaneously select USA, Canada, United Kingdom, Australia, South Africa, Brazil and the EU as targeted regions with conditional Consent and dedicated Cookie Banners. Support for GDPR / ePrivacy – European Union with Extension for Switzerland. Support for USA / CCPA/CPRA/CPA/CTDPA/NRS 603A/UCPA/VCDPA Support for UK-GDPR / PECR and ICO Guidelines – United Kingdom. Support for PIPEDA and CASL – Canada. Support for Privacy Act 1988 & Australian Privacy Principles Support for POPIA, the South African Protection of Personal Information Act Supports The “Marco Civil” and the Brazilian General Data Protection Law (LGPD) Legal Documents Privacy statements (EU, CA, UK, AU, ZA, BR & USA). Cookie policy (EU, UK, CA, AU, ZA, BR & USA). Impressum (Germany & Austria) & Imprint for world wide use. Disclaimer Terms & Conditions Integration Processing agreements (EU, UK, CA, AU, ZA, BR & USA). Dataleak reporting tools (EU, UK, CA, AU, ZA, BR & USA). Supports CCPA Consent and Legal documents. COPPA ready with Children’s Privacy Policy (USA) Children’s Privacy Policy (UK,CA & AU) Support & Updates Premium Support from our amazing team. Premium updates, new languages, features, regions and more to create the Ultimate Privacy Suite for WordPress. About Complianz Check out other plugins developed by Really Simple Security as well: Really Simple Security Complianz is on GitHub as well! IMPORTANT! Complianz | GDPR/CCPA Cookie Consent can help you meet compliance requirements, but the user must ensure that all requirements are met. Complianz provides your Cookie Policy with comprehensive cookie descriptions, supplied by cookiedatabase.org, operated by Complianz B.V. The plugin sends the results of Complianz’ local or advanced website scan to Cookiedatabase.org, for the sole purpose of providing you with accurate descriptions and keeping them up-to-date on a regular basis. The advanced website scan can be initialized after authentication and consent for security purposes. We collect for research purposes: Cookie names Domain that provides the cookie names Plugin list on the domain For more information: Cookiedatabase.org – Privacy Statement Cookiedatabase.org – Terms and Conditions Database Cookiedatabase.org – Terms of Use API For security purposes, we authenticate the advanced website scan with: Email address The advanced website scan collects public data from the user’s site, stores it for one hour, and then discards it without analysis. For more information: Advanced website scan Complianz.io – Privacy Statement Advanced website scan Complianz.io – Terms of Use API Contact us if you have any questions, issues, or suggestions. Complianz | GDPR/CCPA Cookie Consent is developed by Complianz B.V..

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C