Junglewise Threat Intelligence

CVE-2026-65498: Complianz GDPR sensitive data exposure

CVE-2026-65498 · Severity: medium · CVSS 5.3 · Published 2026-07-23

Executive brief

Complianz is a popular WordPress plugin used to manage legal compliance and cookie consent. A security flaw in versions 7.5.0 and earlier allows unauthenticated visitors to access sensitive system information that should be restricted. While this does not directly allow site takeover, the exposed data can be used by attackers to plan more sophisticated follow-up attacks.

Technical details

A sensitive data exposure vulnerability (CWE-497) exists in the Complianz plugin for WordPress in versions up to and including 7.5.0. The vulnerability allows an unauthenticated remote attacker to access sensitive system information due to improper restriction of the control sphere. The attack can be carried out over the network without any user interaction. At the time of the advisory, no official patch has been confirmed, though users are advised to monitor for updates from the developer.

Affected products

  • Complianz Complianz - GDPR/CCPA Cookie Consent <= 7.5.0

Timeline

  • 2026-06-24: other: Reported by researcher to Patchstack
  • 2026-07-22: advisory: Patchstack advisory published
  • 2026-07-23: disclosed: NVD publication date

References