Описание
The GDPR Cookie Compliance plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the gdpr_cookie_compliance_reset_settings AJAX action in versions up to, and including, 4.0.2. This makes it possible for authenticated attackers to reset all of the settings.
Ссылки
- Exploit
- Third Party Advisory
- Third Party Advisory
- Broken LinkThird Party Advisory
- Exploit
- Third Party Advisory
- Third Party Advisory
- Broken LinkThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.0.3 (исключая)
cpe:2.3:a:mooveagency:gdpr_cookie_compliance:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 8%
0.0003
Низкий
5.4 Medium
CVSS3
4.3 Medium
CVSS3
Дефекты
CWE-862
Связанные уязвимости
CVSS3: 5.4
github
больше 2 лет назад
The GDPR Cookie Compliance plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the gdpr_cookie_compliance_reset_settings AJAX action in versions up to, and including, 4.0.2. This makes it possible for authenticated attackers to reset all of the settings.
EPSS
Процентиль: 8%
0.0003
Низкий
5.4 Medium
CVSS3
4.3 Medium
CVSS3
Дефекты
CWE-862