CVE-2026-16613

GDPR Cookie Compliance < 5.1.0 - Cookie Deletion and Forced Logout via CSRF

The GDPR Cookie Compliance WordPress plugin before 5.1.0 expires the visitor's cookies from an action that is reachable without authentication and performs no request-origin check, allowing an attacker to log any user out and delete the site's cookies by luring them to a crafted link.


We have discovered 86,497 live websites that are affected by CVE-2026-16613.

Run a Free Instant Scan




Affected Software

Product  GDPR Cookie Compliance
Category Cookie compliance
Vulnerable Domains86,497 live websites (91% of GDPR Cookie Compliance install base)
Vulnerable Versions
  • from 0 through 5.1
Vulnerable Versions Count163 versions ( 99% of all versions)


Common Weakness Enumeration

CWE-352 Cross-Site Request Forgery (CSRF)



Details

  • Published - Aug 5, 2026
  • Updated - Aug 5, 2026

Credits

  • Abdullah Kareem (cyberkareem) (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-16613
United States10,163 websites



Spain15,605 websites
Germany11,492 websites
France5,758 websites
GB5,196 websites
Italy5,029 websites
Poland4,241 websites
Hungary3,068 websites
Romania2,284 websites
Brazil2,122 websites

Website Distribution by TLD

Number of websites using CVE-2026-16613
.com28,225 websites
.de7,021 websites
.es6,587 websites
.co.uk3,519 websites
.it3,490 websites
.pl3,327 websites
.org2,768 websites
.fr2,396 websites
.com.br1,983 websites
.nl1,850 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-16613

Top websites that are affected by CVE-2026-16613. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.org United States*,***
***.com United States*,***
*****.**.uk United States**,***
*******.co Serbia**,***
***.********.edu United States**,***
****************.ai United States**,***
******.com United States**,***
******.com United States**,***
*******.app United States**,***
****.org United States**,***
See full domain list

FAQ

CVE-2026-16613 is Cross-Site Request Forgery (CSRF) in GDPR Cookie Compliance
A total of 86,497 websites have been identified as vulnerable to CVE-2026-16613, based on global website indexing conducted by WebTechSurvey.
The GDPR Cookie Compliance is affected by the CVE-2026-16613 vulnerability.
GDPR Cookie Compliance versions up to 5.1 are vulnerable to CVE-2026-16613.
CVE-2026-16613 is resolved in version 5.1 of GDPR Cookie Compliance.