The GDPR Cookie Compliance WordPress plugin before 4.15.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
We have discovered 26,074 live websites that are affected by CVE-2025-1622.
| Product | |
| Category | Cookie compliance |
| Vulnerable Domains | 26,074 live websites (73% of GDPR Cookie Compliance install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 152 versions ( 97% of all versions) |
| 2,045 websites | |
| 4,558 websites | |
| 3,973 websites | |
| 2,346 websites | |
| 1,676 websites | |
| 1,276 websites | |
| 1,173 websites | |
| 1,111 websites | |
| 911 websites | |
| 708 websites |
| .com | 8,119 websites |
| .de | 2,420 websites |
| .es | 1,979 websites |
| .it | 1,590 websites |
| .pl | 983 websites |
| .co.uk | 786 websites |
| .com.br | 673 websites |
| .org | 561 websites |
| .fr | 512 websites |
| .net | 432 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****.**.uk | **,*** | ||
| *******.co | **,*** | ||
| ****************.ai | **,*** | ||
| *******.app | **,*** | ||
| *****.es | **,*** | ||
| *******.com | **,*** | ||
| **********.com | **,*** | ||
| **************************.pt | **,*** | ||
| ***********.com | **,*** | ||
| *****.com | **,*** |
FAQ