WF Cookie Consent

WF Cookie Consent has one disclosed vulnerability in the WordSec catalog, all reported in 2018; it is fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).

The one issue recorded for WF Cookie Consent has a vendor fix available, so running the current release closes it.

All of these findings were reported by B0UG. WF Cookie Consent is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSMedium
6.1/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all WF Cookie Consent vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.1CVE-2018-10371

WF Cookie Consent <= 1.1.3 - Cross-Site Scripting

Read the full analysis

Vulnerability Records

1 records
Showing 1–1 of 1 reports
WF Cookie Consent banner
Latestv1.3

WF Cookie Consent

wunderfarm

Author

wunderfarm

5.0(27)
100/100
Last Updated
2026-06-29 (3mo ago)
Active Installs
10,000+
Downloads
784,894
Requires WP
4.7+
Requires PHP
7.0+
Tested up to
WP 7.0.4
Created
2015-05-22 (12y ago)

WF Cookie Consent shows the user a clear message that the site uses cookies. This plugin supports multi-language installations with the polylang-plugin from Chouby or WPML-plugin from wpml.org. It has a wide array of settings for controlling the style and contents. WF Cookie Consent is the “wunderfarm-way” to show how your website complies with the EU Cookie Law.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C