Impact
The My Agile Privacy® plugin suffers from an authorization bypass flaw where AJAX actions map_missing_cookie_shield and map_check_consent_mode_status are not protected against unauthenticated access. This flaw enables an attacker to alter key configuration options such as missing_cookie_shield, cookie_shield_running, and various consenus mode parameters stored in the plugin settings. The impact expands to potential manipulation of cookie consent logic, which could affect user privacy compliance and the running of client‑side scripts. The weakness is a classic Missing Authorization issue (CWE‑862).
Affected Systems
All WordPress sites running the My Agile Privacy® – CMP, Cookie Consent & Privacy Tools plugin version 3.3.6 or older are affected. The vulnerability is present in the plugin’s AJAX handlers and therefore applies to any installation where the plugin is active, regardless of the site’s overall configuration.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity vulnerability. The EPSS score is not reported, but the lack of authentication checks implies that exploitation does not require specialized knowledge or privileged access. The plugin has not been flagged in the CISA KEV catalog, suggesting no widespread incident reports yet. Attackers can reach the vulnerable AJAX actions directly via HTTP requests, and no additional network or host conditions are required. Because the flaw grants direct control over privacy‑relevant settings, a successful exploit could compromise the integrity and reliability of the consent framework on the affected site.
OpenCVE Enrichment