Impact
A CWE-89 vulnerability exists in the Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress, allowing generic SQL Injection through the 's' parameter in all versions up to and including 4.3.5. The flaw stems from insufficient escaping of user-supplied data and lack of prepared statements, enabling an attacker with Administrator-level access to append arbitrary SQL commands to existing queries. This can lead to extraction or alteration of sensitive database contents, thereby compromising confidentiality, integrity, or availability of the site’s data.
Affected Systems
All releases of the Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin up to and including version 4.3.5 are affected. WordPress sites that have any of these versions installed are vulnerable, and the flaw can be exploited by any user who holds an Administrator role or higher.
Risk and Exploitability
The CVSS score of 4.9 reflect a moderate overall severity level. The EPSS score is below 1 %, indicating a very low probability of exploitation. The vulnerability is not listed in the Cers therefore need authenticated access with administrator privileges, limiting the pool to site owners or insiders, but once a privileged user supplies crafted input through the plugin’s administrative interface, arbitrary SQL can be executed. The impact on a compromised site could allow attackers to read, modify, or delete database records.
OpenCVE Enrichment