Impact
A missing authorization check in the Ninja Team GDPR CCPA Compliance Support plugin allows an attacker to access the plugin’s configuration interface by exploiting incorrectly configured access control. This can enable the attacker to alter compliance settings, potentially exposing sensitive user data or disabling compliance features. The weakness is classified as Missing Authorization (CWE‑862).
Affected Systems
The vulnerability affects the Ninja Team GDPR CCPA Compliance Support WordPress plugin for all releases up to and including version 2.7.3. The plugin is distributed by Ninja Team and used on WordPress sites that require GDPR and CCPA compliance support.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate impact, while the EPSS score of less than 1% suggests a low probability of exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. Exploitation would likely occur through a web-based attack vector that targets the plugin’s configuration pages, requiring sufficient user authentication to reach the affected routes. Even with low exploitation likelihood, the potential exposure of compliance settings warrants prompt attention.
OpenCVE Enrichment
EUVD