Impact
The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent WordPress plugin is vulnerable to generic SQL injection through the 's' parameter in all releases up to 4.3.5. The flaw arises from insufficient escaping of user‑supplied data and the lack of prepared statements, enabling an authenticated administrator or higher to append arbitrary SQL commands to existing database queries. This allows the attacker to read, modify, or delete sensitive database information, compromising data confidentiality and integrity.
Affected Systems
Any WordPress site that has the Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin installed at version 4.3.5 or earlier is affected. The vulnerability can be exploited only by users who possess Administrator privileges or higher within the WordPress environment.
Risk and Exploitability
The CVSS score of 4.9 indicates a moderate severity. The EPSS score is below 1 %, suggesting a very low exploitation probability in the general WordPress ecosystem. The vulnerability is not listed in the CISA KEV catalog. Because the flaw requires authenticated access with administrator-level privileges, the attack surface is limited to site owners or trusted internal users. Once an authorized user supplies crafted input via the plugin's administrative interface, arbitrary SQL can be executed, potentially exposing or destroying the site’s stored data.
OpenCVE Enrichment