Impact
The WPLP Cookie Consent WordPress plugin versions before 4.4.2 omits nonce or capability checks on the gcc_get_schedule_scan AJAX action. This omission permits any authenticated user, for example a subscriber, to retrieve the automated scan schedule that an administrator has configured, exposing scheduling details without authorization.
Affected Systems
WordPress sites that have installed the WPLP Cookie Consent plugin in any release between 4.0.2 and 4.4.1 are affected. The vulnerability exists in all these releases and spans any deployment of the plugin regardless of site configuration.
Risk and Exploitability
Once an attacker obtains valid credentials for a user with any authenticated role they can call the vulnerable AJAX endpoint and read the scan schedule. Although this does not grant direct administrative functions or data modification, it does leak configuration information that could be used for social engineering or further reconnaissance. The EPSS score is <1%, and the vulnerability is not listed in CISA KEV, indicating that public exploitation evidence is currently limited. The CVSS score of 4.3 reflects a moderate severity assessment.
OpenCVE Enrichment