Impact
The GDPR Cookie Compliance WordPress plugin contains a CSRF vulnerability that allows an unauthenticated attacker to trigger a guest‑friendly action that deletes visitor cookies and logs any user out. A crafted link sent to a target will perform the action without any request‑origin checks. The resulting impact is loss of session state and forced logout, which can disrupt user workflow and potentially expose the site to further credential‑stealing attacks if the user re‑authenticates over an insecure channel.
Affected Systems
WordPress sites running the GDPR Cookie Compliance plugin in versions earlier than 5.1.0 are vulnerable. The vulnerability is present in all builds before 5.1.0 and affects sites that have not been updated to the patched release.
Risk and Exploitability
The attack vector relies on CSRF and requires only a crafted link to be opened by the victim. Because the endpoint is publicly reachable without authentication and does not perform any origin verification, exploitation is straightforward. The exploitation probability is unclear due to the lack of an EPSS score, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, an attacker can achieve a denial‑of‑service style effect by repeatedly forcing users to log out and clearing cookies.
OpenCVE Enrichment