Cross-Site Request Forgery Vulnerability in Shahjahan Jewel WP GDPR Cookie Consent Plugin
CVE-2025-53316

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
6 November 2025

What is CVE-2025-53316?

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Shahjahan Jewel WP GDPR Cookie Consent plugin. This flaw allows attackers to perform unauthorized actions on behalf of the users, potentially leading to stored cross-site scripting (XSS) issues. The vulnerability affects versions of the plugin up to and including 1.0.0. It is crucial for users of this plugin to implement security measures to mitigate risks associated with CSRF attacks.

Affected Version(s)

WP GDPR Cookie Consent 0 <= 1.0.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Skalucy | Patchstack Bug Bounty Program
.