Impact
The vulnerability in the Cookies and Content Security Policy plugin allows the insertion of sensitive information into data sent via cookies, enabling attackers to retrieve embedded sensitive data. This flaw compromises confidentiality by exposing private information that should not be transmitted in or stored within client‑side cookies. The weakness is classified as CWE‑201, Sensitive Information Exposure.
Affected Systems
Affected are WordPress sites running the Cookies and Content Security Policy plugin by Johan Jonk Stenström, any version up to and including 2.34. The problem applies to all releases from the initial release through 2.34, so any site using an outdated plugin version is vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate overall risk, but the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The flaw is not currently listed in CISA’s KEV catalog, implying no publicly known exploits. Attackers would need to exploit the plugin within the context of the site, likely requiring authenticated access or the ability to manipulate visitor cookies; thus the attack vector is inferred as local or site‑based rather than a remote network exploitation.
OpenCVE Enrichment