Missing Authorization Flaw in Themebeez Simple GDPR Cookie Compliance Plugin
CVE-2026-24604
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 23 January 2026
What is CVE-2026-24604?
The Themebeez Simple GDPR Cookie Compliance plugin suffers from a missing authorization vulnerability, which arises from incorrectly configured access control security levels. This flaw could allow unauthorized users to exploit the system, potentially leading to unauthorized access to sensitive data. It affects all versions of the plugin up to and including 2.0.0, thus necessitating an urgent update to secure WordPress installations.
Affected Version(s)
Simple GDPR Cookie Compliance 0 <= 2.0.0