Impact
The Cookiebot CMP plugin for WordPress contains a missing capability check in its send_uninstall_survey() function. Authenticated users with Subscriber-level access can invoke the function without authorization, allowing them to submit uninstall survey data as if they were the site administrator. This results in unauthorized data modification and potential tampering of survey metrics, which undermines data integrity and could be used to conduct malicious or deceptive surveys.
Affected Systems
The vulnerability affects the Cookiebot CMP plugin by Usercentrics – Automatic Cookie Banner for GDPR/CCPA & Google Consent Mode on WordPress installations. All releases up to and including version 4.4.1 are vulnerable; any site that has not applied a patch or upgrade beyond 4.4.1 remains exposed.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate impact, while the EPSS score of < 1% shows a low likelihood of exploitation in the wild. The bug is not listed in CISA KEV, which further suggests it has not yet been widely exploited. An attacker would need to compromise or steal credentials for a user with Subscriber+ access, or manipulate the site to elevate privileges. Once such access is achieved, the attacker could submit a survey on behalf of the site, potentially defrauding analytics or reporting.
OpenCVE Enrichment
EUVD