CVE-2026-13360

Cookie Banner for GDPR / CCPA <= 4.3.5 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'regionArray' Parameter

The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'regionArray' parameter in all versions up to, and including, 4.3.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires that the site administrator has enabled the 'Support Google Consent Mode (GCM)' setting, which is disabled by default. Additionally, the AJAX handler performs no nonce or capability check, allowing any authenticated user including those with Subscriber-level access to overwrite the affected plugin setting.


We have discovered 1,005 live websites that are affected by CVE-2026-13360.

Run a Free Instant Scan




Affected Software

Product  GDPR Cookie Consent
Category Cookie compliance
Vulnerable Domains1,005 live websites (100% of GDPR Cookie Consent install base)
Vulnerable Versions
  • from 0 through 4.3.5
Vulnerable Versions Count82 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Aug 15, 2026
  • Updated - Aug 18, 2026

Credits

  • Naoya Takahashi (nakko) (finder)

Website Distribution by Country

Number of websites using CVE-2026-13360
United States217 websites



Spain162 websites
GB115 websites
Germany92 websites
France57 websites
Italy35 websites
Brazil32 websites
Austria25 websites
Czech Republic25 websites
Poland23 websites

Website Distribution by TLD

Number of websites using CVE-2026-13360
.com423 websites
.co.uk92 websites
.es62 websites
.de48 websites
.com.br29 websites
.it27 websites
.at25 websites
.net24 websites
.cz24 websites
.org23 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-13360

Top websites that are affected by CVE-2026-13360. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.*****.com United States***,***
*******.ca Canada***,***
*************.com United States***,***
***************.com Belgium***,***
**************.com Slovakia***,***
***************.com United States***,***
************.com United States***,***
************.**.jp Japan***,***
*************.de United States***,***
*************.de Germany*,***,***
See full domain list

FAQ

CVE-2026-13360 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GDPR Cookie Consent
A total of 1,005 websites have been identified as vulnerable to CVE-2026-13360, based on global website indexing conducted by WebTechSurvey.
The GDPR Cookie Consent is affected by the CVE-2026-13360 vulnerability.
GDPR Cookie Consent versions up to and including 4.3.5 are vulnerable to CVE-2026-13360.

References