Impact
This vulnerability results from missing authorization checks in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent, enabling attackers to manipulate or read plugin settings regardless of user permissions. The primary consequence is the ability to alter consent configurations or access information typically reserved for administrators, potentially exposing user data or disrupting compliance controls.
Affected Systems
WordPress sites running the WP Cookie Notice plugin version 4.0.7 or earlier, including the WP Legal Pages distribution. Sites that have not yet upgraded beyond 4.0.7 are exposed.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score of less than 1% suggests a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. However, the attack vector is likely web based through authenticated or unauthenticated requests to plugin endpoints, and any entity with access to the site’s administrative interface could potentially exploit this flaw if the plugin’s access controls are not correctly configured.
OpenCVE Enrichment