CVE-2026-16613 PUBLISHED

GDPR Cookie Compliance < 5.1.0 - Cookie Deletion and Forced Logout via CSRF

Assigner: WPScan
Reserved: 22.07.2026 Published: 05.08.2026 Updated: 05.08.2026

The GDPR Cookie Compliance WordPress plugin before 5.1.0 expires the visitor's cookies from an action that is reachable without authentication and performs no request-origin check, allowing an attacker to log any user out and delete the site's cookies by luring them to a crafted link.

Product Status

Vendor Unknown
Product GDPR Cookie Compliance
Versions Default: unaffected
  • affected from 0 to 5.1.0 (excl.)

Credits

  • Abdullah Kareem (cyberkareem) finder
  • WPScan coordinator

References

Problem Types

  • CWE-352 Cross-Site Request Forgery (CSRF) CWE