Impact
The Cookie‑Script.com WordPress plugin, versions up to and including 1.2.1, has a missing authorisation flaw (CWE‑862). This weakness permits an attacker to bypass the plugin’s access controls and obtain the configuration interface. The vulnerability could enable unauthorized changes to the plugin’s cookie settings, thereby altering how the site manages cookies for visitors.
Affected Systems
WordPress sites that use the Cookie‑Script.com plugin developed by csarturas, any version 1.2.1 or earlier, are vulnerable.
Risk and Exploitability
The CVSS score of 5.3 denotes a moderate severity, while an EPSS score of less than 1 % indicates a very low probability of exploitation. The flaw is not listed in the CISA KEV catalog. Exploitation would likely require access to the WordPress administrative interface or the plugin’s management pages; no remote code execution capability is disclosed. The combination of moderate severity and low exploitation likelihood suggests remediation is advisable but the risk is not immediately critical.
OpenCVE Enrichment
EUVD