Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xw6w-vrqp-fhq4

Опубликовано: 02 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

The webtoffee-cookie-consent WordPress plugin before 3.5.3 does not perform authorization checks on several of its REST API routes, allowing unauthenticated attackers to export and delete stored visitor consent records, create posts, and modify the webtoffee-cookie-consent WordPress plugin before 3.5.3's licensing state.

The webtoffee-cookie-consent WordPress plugin before 3.5.3 does not perform authorization checks on several of its REST API routes, allowing unauthenticated attackers to export and delete stored visitor consent records, create posts, and modify the webtoffee-cookie-consent WordPress plugin before 3.5.3's licensing state.

EPSS

Процентиль: 12%
0.00216
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

nvd
2 дня назад

The webtoffee-cookie-consent WordPress plugin before 3.5.3 does not perform authorization checks on several of its REST API routes, allowing unauthenticated attackers to export and delete stored visitor consent records, create posts, and modify the webtoffee-cookie-consent WordPress plugin before 3.5.3's licensing state.

EPSS

Процентиль: 12%
0.00216
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-862