Impact
The WPLP Cookie Consent WordPress plugin before version 4.4.4 does not perform CSRF or capability checks when processing bulk actions on its admin screens and does not restrict the targeted items to its own records. An authenticated administrator can therefore send a crafted HTTP request that causes the plugin to permanently delete any post or page on the site regardless of ownership. This flaw allows an attacker who has admin credentials to remove arbitrary content, resulting in data loss and potential site disruption.
Affected Systems
WordPress sites running WPLP Cookie Consent plugin version 4.4.3 or older are affected. Any installation with the unpatched plugin is vulnerable, regardless of other plugins or themes installed.
Risk and Exploitability
The EPSS score indicates less than 1 % likelihood that the flaw is being actively exploited, and it is not listed in the CISA KEV catalog. Nevertheless, the vulnerability requires only an authenticated administrator session and a single crafted HTTP request, making the attack trivial for an attacker who has such credentials. The CVSS score of 6.5 reflects a medium severity that encompasses the potential for data loss from arbitrary content deletion. The lack of a CVSS score in earlier advisories does not change the fact that the flaw can allow administrators to permanently remove any post or page.
OpenCVE Enrichment