The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.5.6. This is due to missing or incorrect nonce validation on the process_delete function in class-DNSMPD.php. This makes it possible for unauthenticated attackers to delete GDPR data requests via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
We have discovered 67,856 live websites that are affected by CVE-2024-1592.
Product | ![]() |
Category | Cookie compliance |
Vulnerable Domains | 67,856 live websites (19.56% of Complianz install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 158 versions ( 86.34% of all versions) |
![]() | 6,990 websites |
![]() | 22,966 websites |
![]() | 8,261 websites |
![]() | 5,782 websites |
![]() | 3,870 websites |
![]() | 2,561 websites |
![]() | 2,083 websites |
![]() | 1,894 websites |
![]() | 1,425 websites |
![]() | 1,390 websites |
.com | 18,771 websites |
.de | 16,247 websites |
.fr | 3,738 websites |
.it | 3,331 websites |
.es | 3,035 websites |
.cz | 2,482 websites |
.nl | 1,840 websites |
.at | 1,802 websites |
.org | 1,381 websites |
.co.uk | 1,127 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*********.com | ![]() | *,*** | |
*************.nl | ![]() | *,*** | |
********.de | ![]() | **,*** | |
*****.com | ![]() | **,*** | |
******.com | ![]() | **,*** | |
*****.de | ![]() | **,*** | |
******.**********.fr | ![]() | **,*** | |
***********.**.gr | ![]() | **,*** | |
******.no | ![]() | **,*** | |
***.********.com | ![]() | **,*** |