Impact
Missing authorization in the WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin allows an attacker to alter or view plugin settings without proper privileges. This is a CWE-862 Broken Access Control weakness. Changes could involve modifying consent banner text or disabling consent checks, thereby compromising the site’s privacy compliance functionality.
Affected Systems
WordPress installations running WP Cookie Notice for GDPR, CCPA & ePrivacy Consent version 4.0.3 or earlier are affected, regardless of the WordPress core version.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Data in the description implies the attack vector likely involves accessing the plugin’s configuration pages, either through the WordPress admin interface or exposed plugin endpoints, requiring the attacker to have some level of access to the site. Once exploited, the adversary could adjust privacy notices or disable required consent mechanisms.
OpenCVE Enrichment