SimaCookie
SimaCookie has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2025; none of them are fixed as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 6.4 out of 10. 2025 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (50%). Other recurring categories include Cross-Site Scripting.
None of the 2 issues recorded for SimaCookie have a published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by Kévin Mosbahi (Mika). SimaCookie is installed on roughly 50 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 5.0.27.
CVE-2025-58868SimaCookie <= 1.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

SimaCookie
Author
Simasicher
Block all cookies without consent and customize the cookie note as you wish. The SimaCookie plugin adapts your website to the new requirements regarding the GDPL. In addition, you can customize the note texts and presentation. With a pop-up, your users will be informed according to your specifications and can decide on the cookie application. The cookie plugin remembers the user’s decision either for the current session or for an adjustable time. The SimaCookie plugin extends the EU Cookie Law plugin with more cookie hints: Overlay that prevents the user from accessing the page without the consent of cookies Bar bottom and top In addition, you can now provide the designated cookies with categories and explain them in more detail with notes. Features Automatic blocking of all cookies without consent (iframes, embeds, scripts) Individual and customizable cookie hint (color, position, text) Customizable categories and explanations for set cookies Consent by click, scrolling and navigation Linking of your own privacy policy Adjustable cookie lifetime Optimized presentation for tablets and smartphones (responsive) Compatible with different languages Compatible with Disqus and Jetpack InfiniteScroll Compatible with caching plugins SEO friendly
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C