CookieCode
CookieCode has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 4.4, and the most serious one scores 4.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for CookieCode has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by Nabil Irawan. CookieCode is installed on roughly 200 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.7.7.
CVE-2025-47668CookieCode <= 2.4.4 - Authenticated (Administrator+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records
CookieCode
Author
cookiecode
CookieCode enables your website to comply with GDPR and e-privacy rules by blocking tracking and analytical cookies until the visitor has given their consent. In addition, the cookie declaration for your website will be updated automatically by our crawler. Third party service CookieCode is a third party service that analyzes your website to look for tracking and analytical cookies. Consent given by the visitor is stored anonymously on our servers for audit purposes. Privacy statement: https://cdn.cookiecode.nl/privacy/www.cookiecode.nl/en/pdf
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C