Impact
A missing authorization check in the Cookiebot WordPress plugin allows an attacker to bypass normal access restrictions. The flaw is present in all releases up to and including version 4.6.4 and could let an attacker view or alter configuration data that should be protected by role‑based controls, potentially exposing privacy or functionality of the website.
Affected Systems
The vulnerability affects installations of the Cookiebot plugin for WordPress where the version is 4.6.4 or earlier; any site running the plugin before version 4.6.5 is considered vulnerable.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate risk profile, while the EPSS score of less than 1% suggests a low likelihood of exploitation at present. Based on the description, it is inferred that an attacker would need to authenticate against the WordPress site with a user role that has at least editor privileges and then access the plugin’s administrative endpoints; the vulnerability is not listed in CISA’s KEV catalog, implying no known active exploitation yet.
OpenCVE Enrichment