CVE-2025-12136 | Real Cookie Banner: GDPR & ePrivacy Cookie Consent Plugin REST API Endpoint scan-without-login server-side request forgery
A vulnerability was found in Real Cookie Banner: GDPR & ePrivacy Cookie Consent Plugin up to 5.2.4 on WordPress. It has been declared as critical. Affected by this issue is some unknown functionality of the file /scanner/scan-without-login of the component REST API Endpoint. The manipulation results in server-side request forgery.
This vulnerability was named CVE-2025-12136. The attack may be performed from remote. There is no available exploit.