Impact
The vulnerability is a missing authorization flaw in the WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin that allows attackers to manipulate the plugin’s cookie banner configuration. By changing wording, placement or regulatory options, an attacker can undermine a site’s privacy compliance and possibly redirect visitors to undesirable content. The flaw is formally identified as CWE‑862 and is present in all plugin releases up to version 4.0.3.
Affected Systems
The affected product is the WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin from WP Legal Pages, with vulnerable versions being all releases through and including 4.0.3. The plugin is commonly deployed on WordPress sites to administer cookie banner compliance.
Risk and Exploitability
The vulnerability carries a CVSS base score of 5.3, indicating moderate severity. The EPSS score is below 1 %, suggesting a low likelihood of exploitation, and it is not listed in the CISA KEV catalog. The likely attack vector is exploiting the plugin’s administrative URLs — an attacker could target a site where the backend endpoints are accessible to users lacking the proper capability. Based on the description, it is inferred that the attacker cannot execute arbitrary code beyond those configuration changes.
OpenCVE Enrichment