Medium 4.3
2026-02-19< 4.6.5
CVE-2026-25407
Minimum safe version
4.6.5
Update to 4.6.5 or later to address 7 fixable vulnerabilities
CVE-2026-25407
CVE-2025-53197
WordPress Cookiebot Plugin <= 4.4.1 is vulnerable to Broken Access Control
Cookiebot | GDPR/CCPA Compliant Cookie Consent and Control <= 3.6.0 - Reflected Cross-Site Scripting
Cookiebot < 3.6.1 - Authenticated Reflected Cross-Site Scripting (XSS)
Cookiebot < 3.6.1 - CSRF & XSS
WordPress Cookiebot plugin <= 3.6.0 - Reflected Cross-Site Scripting (XSS) vulnerability