Impact
The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin contains a generic SQL injection flaw in the ‘scan_id’ parameter. The user‑supplied value is insufficiently escaped and the existing SQL query is not prepared, allowing an authenticated user with administrator privileges or higher to append arbitrary SQL statements. This can expose or modify sensitive data stored in the WordPress database, as the vulnerability is classified as CWE‑89.
Affected Systems
All installations of the WordPress plugin Cookie Banner for GDPR / CCPA – WPLP Cookie Consent that are version 4.3.6 or earlier are affected. This includes every site that has not upgraded beyond 4.3.6.
Risk and Exploitability
The CVSS score of 4.9 indicates moderate severity, while the EPSS score of less than probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attacks require authenticated administrator access; an attacker who can log in with privileged credentials can execute the injected SQL to read or alter database contents, potentially compromising confidentiality and integrity.
OpenCVE Enrichment