WP Cookies Enabler

WP Cookies Enabler has one disclosed vulnerability in the WordSec catalog, all reported in 2024; it remains unpatched as of September 2026. Their average CVSS score is 9.8, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 0 high.

The most common weakness is PHP Remote File Inclusion, behind 1 of the records (100%).

The one issue recorded for WP Cookies Enabler has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2024.

All of these findings were reported by tahu.datar. WP Cookies Enabler is installed on roughly 20 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 4.4.34.

Strategic Overview

Avg CVSSCritical
9.8/ 10
Patch Coverage0%
Open

1

Fixed

0

Get automatic notifications for all WP Cookies Enabler vulnerabilities before they are exploited.

Most severe open issueCVSS 9.8CVE-2024-54380

WP Cookies Enabler <= 1.0.1 - Unauthenticated Local File Inclusion

Read the full analysis

Vulnerability Records

1 records
WP Cookies Enabler banner
Latestv1.0.1

WP Cookies Enabler

Filippo Bodei

Author

Filippo Bodei

5.0(2)
100/100
Last Updated
2016-01-12 (11y ago)
Active Installs
20+
Downloads
2,456
Requires WP
3.0.1+
Requires PHP
0+
Tested up to
WP 4.4.34
Created
2015-10-10 (11y ago)

EUROPEAN websites must follow the Commission’s guidelines on privacy and data protection and inform users that cookies are not being used to gather information unnecessarily. The ePrivacy directive – more specifically Article 5(3) – requires prior informed consent for storage or for access to information stored on a user’s terminal equipment. In other words, you must ask users if they agree to most cookies and similar technologies before the site starts to use them. For consent to be valid, it must be informed, specific, freely given and must constitute a real indication of the individual’s wishes. WP Cookies Enabler is an easy and lightweight solution to preventively block third-party cookies installed by js and to comply with the EU cookie law. Features: Display notice banner out of the box Fully customizable aspect Works on script tags, iframes, and asynchronous scripts Lighweight: only load styles when the banner is displayed Disclaimer ALL THE COMPUTER PROGRAMS AND SOFTWARE ARE PROVIDED “AS IS” WITHOUT WARRANTY OF ANY KIND. WE MAKE NO WARRANTIES, EXPRESS OR IMPLIED, THAT THEY ARE FREE OF ERROR, OR ARE CONSISTENT WITH ANY PARTICULAR STANDARD OF MERCHANTABILITY, OR THAT THEY WILL MEET YOUR REQUIREMENTS FOR ANY PARTICULAR APPLICATION. THEY SHOULD NOT BE RELIED ON FOR SOLVING A PROBLEM WHOSE INCORRECT SOLUTION COULD RESULT IN INJURY TO A PERSON OR LOSS OF PROPERTY. IF YOU DO USE THEM IN SUCH A MANNER, IT IS AT YOUR OWN RISK. THE AUTHOR AND PUBLISHER DISCLAIM ALL LIABILITY FOR DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES RESULTING FROM YOUR USE OF THE PROGRAMS.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C