Cross-Site Request Forgery Vulnerability in Shahjahan Jewel WP GDPR Cookie Consent Plugin
CVE-2025-53316

8.8HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
6 November 2025

What is CVE-2025-53316?

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Shahjahan Jewel WP GDPR Cookie Consent plugin. This flaw allows attackers to perform unauthorized actions on behalf of the users, potentially leading to stored cross-site scripting (XSS) issues. The vulnerability affects versions of the plugin up to and including 1.0.0. It is crucial for users of this plugin to implement security measures to mitigate risks associated with CSRF attacks.

Affected Version(s)

WP GDPR Cookie Consent <= n/a

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Skalucy | Patchstack Bug Bounty Program
.