Impact
The WPLP Cookie Consent WordPress plugin before version 4.4.2 does not perform capability or nonce checks on certain A/B testing actions. As a result, any authenticated user—including users with the subscriber role—can overwrite the cookie banner configuration displayed to all visitors and irreversibly reset stored A/B test results. This mixture of configuration tampering and data loss is an example of improper access control (CWE‑862).
Affected Systems
Any WordPress site that has the WPLP Cookie Consent plugin installed with a version earlier than 4.4.2 is vulnerable. The vendor identifier is listed as Unknown:WPLP Cookie Consent but the impact applies to all installations using the affected versions of the plugin.
Risk and Exploitability
The vulnerability can be exploited by simply logging into the WordPress admin area with a subscriber account and navigating to the plugin’s A/B testing section. No elevated privileges, network access, or additional software are required. EPSS score is < 1% and it is not listed in CISA KEV. The CVSS score is 4.3, indicating a moderate severity. The impact remains moderate to high due to its ability to alter site configuration and permanently delete analytics data, but the attack vector relies solely on authenticated access that is typically accessible to many users.
OpenCVE Enrichment