CVE-2026-4019Disclosure

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to unauthorized data access in all versions up to, and including, 7.4.5 This is due to the REST API endpoint at /wp-json/complianz/v1/consent-area/{post_id}/{block_id} using __return_true as the permission_callback, allowing any unauthenticated user to access it. The cmplz_rest_consented_content() function retrieves a post by ID via get_post() and returns the consentedContent attribute of any complianz/consent-area block found in it, without checking if the post is published or if the user has permission to read it. This makes it possible for unauthenticated attackers to read the consent area block content from private, draft, or unpublished posts.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-29); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-29: 1Mentions · 2026-04-30: 1Technical Details · 2026-04-29: 104-2904-30
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-291
Disclosure1
2026-04-301
General1
Full discourse2 posts
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-4019 📊 Severity: 5.3 🚨 Risk Level: Medium 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4019 #CVE-2026-4019 #CVE #Medium #Wordpress #CyberSecurity #InfoSec https://t.co/fmFz5K85MD

    Post summary

    A new CVE (CVE-2026-4019) affecting WordPress with medium severity is announced, but no exploit, patch, or technical details are provided.

    0000032
    143 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4019 The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to unauthorized data access in all versions up to, and including, 7.4.5 This is due to the R… https://www.cve.org/CVERecord?id=CVE-2026-4019

    Post summary

    CVE‑2026‑4019 reveals an unauthorized data access flaw in the Complianz WordPress plugin up to version 7.4.5; the post does not provide any PoC, exploit, patch, or evidence of active exploitation.

    00000115
    57.3K followersView on X

Explore more