Impact
The Civic Cookie Control plugin for WordPress contains a missing authorization flaw that allows attackers to exploit incorrectly configured access control security levels. This vulnerability can enable unauthorized users to access or modify functionality that is intended to be restricted to privileged users, potentially leading to data exposure or manipulation of cookie consent settings. The weakness is categorized as "Missing Authorization" under CWE‑862.
Affected Systems
WordPress sites that use the Civic Cookie Control plugin version 1.53 or earlier, developed by Tasos Fel. Any installation running the plugin at version 1.53 or any earlier released version is impacted.
Risk and Exploitability
The CVSS v3 score of 5.3 indicates moderate risk. The EPSS score of less than 1% suggests a low likelihood of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The lack of explicit statement about the attack vector infers a remote web-based exploitation path, where an attacker submits crafted requests to the plugin’s managed endpoints to bypass user authorization controls.
OpenCVE Enrichment