Unauthorized Data Modification in WP Cookie Consent Plugin for WordPress
CVE-2025-14061
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 17 December 2025
What is CVE-2025-14061?
The WP Cookie Consent plugin for WordPress contains a security flaw in the gdpr_delete_policy_data function. This vulnerability allows unauthorized users to modify or permanently delete posts, pages, attachments, and various post types by exploiting the lack of a capability check. All versions up to and including version 4.0.7 are affected. As a result, attackers can manipulate crucial site data, leading to potential information loss and compliance issues with GDPR and other data protection regulations.
Affected Version(s)
Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Consent * <= 4.0.7