Executive brief
Complianz is a popular WordPress plugin used to manage legal compliance and cookie consent. A security vulnerability in versions 7.5.0 and earlier allows an attacker with 'Author' level permissions to force the website to make unauthorized requests to internal or external servers. This could lead to the exposure of sensitive information from other services running on the same network or system.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in the Complianz plugin for WordPress (versions <= 7.5.0). The flaw allows an authenticated user with 'Author' privileges to trigger the server to perform arbitrary web requests. This is classified under CWE-918 and can be used to probe internal network services or access sensitive data that is not intended to be public. The attack requires high privileges (Author role) and has a high complexity (AC:H) according to the CVSS vector. As of the advisory date, no official patch has been confirmed.
Affected products
- Complianz Complianz GDPROnly (Premium) / GDPR/CCPA Cookie Consent <= 7.5.0
Timeline
- 2026-06-24: other: Vulnerability reported by researcher
- 2026-07-22: advisory: Patchstack advisory published
- 2026-07-23: disclosed: CVE published to NVD