Impact
The WPLP Cookie Consent plugin executes code to store visitor consent on every front‑end page load without performing any authorization or CSRF checks. As a result, an attacker can submit arbitrary data and overwrite the global consent option. The attacker can change settings such as disabling cookie notices, enabling third‑party scripts, or altering compliance flags, thereby undermining the site’s privacy assurances.
Affected Systems
WPLP Cookie Consent for WordPress, any installation using a version earlier than 4.4.2. The vulnerability applies to all WordPress sites that have the plugin installed and running the vulnerable code path.
Risk and Exploitability
The EPSS score is less than 1%, indicating a relatively low likelihood of exploitation and the vulnerability is not listed in the CISA KEV catalog, yet the attack surface is high: any unauthenticated visitor can trigger the vulnerable function by accessing the site’s public URLs. Because there are no authentication or CSRF defenses, the attacker simply needs to send a crafted HTTP request to the front‑end endpoint, making the vulnerability easy to exploit on any reachable installation of the affected plugin. The consequence is a site‑wide configuration change that can be used to force the site to misrepresent user consent or to re‑enable data collection scripts. The vulnerability’s CVSS score of 5.3 indicates moderate severity.
OpenCVE Enrichment