The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.3.7. This is due to missing or incorrect nonce validation on the process_bulk_action function. This makes it possible for unauthenticated attackers to permanently delete or forcibly resolve arbitrary GDPR data request records stored in the wpl_data_req table via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
We have discovered 1,063 live websites that are affected by CVE-2026-15136.
| Product | |
| Category | Cookie compliance |
| Vulnerable Domains | 1,063 live websites (100% of GDPR Cookie Consent install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 82 versions ( 100% of all versions) |
| 229 websites | |
| 166 websites | |
| 123 websites | |
| 98 websites | |
| 61 websites | |
| 40 websites | |
| 36 websites | |
| 27 websites | |
| 26 websites | |
| 24 websites |
| .com | 441 websites |
| .co.uk | 100 websites |
| .es | 64 websites |
| .de | 49 websites |
| .it | 32 websites |
| .com.br | 32 websites |
| .at | 26 websites |
| .cz | 26 websites |
| .org | 25 websites |
| .net | 24 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ****.*****.com | ***,*** | ||
| *******.ca | ***,*** | ||
| *************.com | ***,*** | ||
| ***************.com | ***,*** | ||
| **************.com | ***,*** | ||
| ***************.com | ***,*** | ||
| ************.com | ***,*** | ||
| ************.**.jp | ***,*** | ||
| *************.de | ***,*** | ||
| *************.de | *,***,*** |
FAQ