What is CVE-2026-16613?
CVE-2026-16616 is a vulnerability in the 'GDPR Cookie Compliance' WordPress plugin up to version 4.5.2, where an unauthenticated action expires visitor cookies and lacks a request-origin check. An attacker can log out any user and delete site cookies by luring them to a crafted link. Updating the plugin to version 4.5.2 is recommended.
Azərbaycanca: CVE-2026-16616, WordPress-in 4.5.2 versiyasına qədər olan "GDPR Cookie Compliance" plaginində autentifikasiya tələb etməyən bir funksiyada zəiflikdir. Təcavüzkar saxta link vasitəsilə istifadəçiləri təsadüfən sistemdən çıxara və bütün sayt kukilərini silə bilər. Plaginin 4.5.2 versiyasına yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-352
FAQ2
Which WordPress plugin is affected by CVE-2026-16616?
CVE-2026-16616 affects the 'GDPR Cookie Compliance' plugin.
How can an attacker exploit CVE-2026-16616?
An attacker can log out any user and delete site cookies by luring them to a crafted link.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.