Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Consent <= 4.1.2 - Missing Authorization to Sensitive Information Exposure
2026-02-18 14:54
Rafshanzani SuhadaStrategic Overview
StatusPatched in 4.1.3
Affected PluginWPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode
Affected Version
<= 4.1.2CVSS7.5High
CVE
CVE-2025-11754Vulnerability Overview
The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'gdpr/v1/settings' REST API endpoint in all versions up to, and including, 4.1.2. This makes it possible for unauthenticated attackers to retrieve sensitive plugin settings including API tokens, email addresses, account IDs, and site keys.
Technical Analysis
REMEDIATION: Update to version 4.1.3, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C