Impact
The vulnerability is a missing authorization flaw in the WordPress GDPR Cookie Notice plugin (themeqx). It allows an attacker to alter configuration settings without proper permission checks. The attack can result in an unauthorized change of cookie notice options, potentially leading to privacy compliance violations or misleading users about cookie usage. The weakness is tracked as CWE-862 and carries a CVSS score of 5.3.
Affected Systems
The issue impacts the GDPR Cookie Notice plugin from 0.x up to and including version 1.2.0. Any WordPress site that has installed this plugin in those versions is affected. The plugin is supplied by themeqx.
Risk and Exploitability
With a CVSS of 5.3 the vulnerability is considered moderate. The EPSS score of less than 1 % indicates a low probability of exploitation in the wild, and it is not listed in CISA’s KEV catalog. The attack vector is most likely through the web application interface; an attacker who can reach the WordPress admin area could interact with the plugin’s settings page. Because the core problem is a missing authorization check, an attacker does not need to exploit code execution or injection. The likely method is to access the configuration screens via crafted HTTP requests or the admin UI, bypassing intended permission controls.
OpenCVE Enrichment
EUVD