The Complianz GDPR/CCPA Cookie Consent Banner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content. This vulnerability affects all versions up to, and including, 7.5.4 due to insufficient input sanitization and output escaping. Successful exploitation requires an administrator to approve the attacker's comment, and the site must have both the Elementor plugin installed and [truncated]
The Complianz plugin version 7.5.0 or earlier has an unauthenticated sensitive data exposure vulnerability. This vulnerability, tracked as CVE-2026-65498, has a CVSS score of 5.3 and is classified as medium severity. The vulnerability was published on 2026-07-23T12:18:43.160Z. Administrators and users of Complianz plugin version 7.5.0 or earlier should be aware of this vulnerability and take necessary act [truncated]