PT-2026-57116 · WordPress · Gdpr Cookie Consent
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
GDPR Cookie Consent versions prior to 4.3.7
Description
The plugin allows unauthorized modification of data because the
gdpr cookie consent ajax save schedule scan() function (associated with the wp ajax gcc save schedule scan AJAX action) lacks a capability check and nonce verification. A nonce is a unique token used to prevent replay attacks. This flaw enables authenticated users with Subscriber-level access or higher to modify the cookie scan schedule configuration stored in the gdpr scan schedule data option, a task that should be restricted to users with the manage options capability.Recommendations
Update the plugin to version 4.3.7 or later.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gdpr Cookie Consent