The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the gdpr_cookie_consent_ajax_save_schedule_scan() function (the wp_ajax_gcc_save_schedule_scan AJAX action) in versions up to, and including, 4.3.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify the plugin's cookie scan schedule configuration stored in the gdpr_scan_schedule_data option, which is an administrative function intended to be limited to users with the manage_options capability.
We have discovered 1,063 live websites that are affected by CVE-2026-12955.
| Product | |
| Category | Cookie compliance |
| Vulnerable Domains | 1,063 live websites (100% of GDPR Cookie Consent install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 82 versions ( 100% of all versions) |
| 229 websites | |
| 166 websites | |
| 123 websites | |
| 98 websites | |
| 61 websites | |
| 40 websites | |
| 36 websites | |
| 27 websites | |
| 26 websites | |
| 24 websites |
| .com | 441 websites |
| .co.uk | 100 websites |
| .es | 64 websites |
| .de | 49 websites |
| .it | 32 websites |
| .com.br | 32 websites |
| .at | 26 websites |
| .cz | 26 websites |
| .org | 25 websites |
| .net | 24 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ****.*****.com | ***,*** | ||
| *******.ca | ***,*** | ||
| *************.com | ***,*** | ||
| ***************.com | ***,*** | ||
| **************.com | ***,*** | ||
| ***************.com | ***,*** | ||
| ************.com | ***,*** | ||
| ************.**.jp | ***,*** | ||
| *************.de | ***,*** | ||
| *************.de | *,***,*** |
FAQ