Cookie-Script.com
Cookie-Script.com has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10.
The most common weakness is Missing Authorization, behind 1 of the records (100%).
The one issue recorded for Cookie-Script.com has a vendor fix available, so running the current release closes it.
All of these findings were reported by domiee13. Cookie-Script.com is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2025-49993Cookie-Script.com <= 1.2.1 - Missing Authorization
Read the full analysisVulnerability Records

Cookie-Script.com
Author
csarturas
CookieScript helps your WordPress site meet privacy requirements like GDPR, CPRA, PIPEDA and more. It adds a cookie banner to your site—no need to edit files or write any code yourself. You can use it right after installing, even without a CookieScript account. Later on, if you want to adjust how the banner looks or behaves, you can link an account to unlock more options. The plugin works with Google Consent Mode v2 and the WP Consent API, and can block third-party cookies until a visitor gives permission. It keeps your site compliant without interfering with tools like Google Analytics or ads. More details are available at cookie-script.com. External services This plugin utilizes Cookie-Script.com services to function. 1. Cookie-Script.com API * Service: Scans your website for cookies and retrieves configuration/status. * Data Sent: Website URL, Privacy Policy URL, Language preference, and a unique scan identifier. * When: During manual scan initiation via the plugin settings. * Privacy Policy: https://cookie-script.com/legal/privacy-policy * Terms of Service: https://cookie-script.com/legal/terms-and-conditions 2. Cookie-Script.com CDN * Service: Delivers the JavaScript file for the cookie banner (for “With Account” mode). * Data Sent: Standard web request data (IP address, User Agent) when fetching the script. * When: On every page load where the banner is active. * Privacy Policy: https://cookie-script.com/legal/privacy-policy
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C