Arbitrary Option Update Vulnerability in Cookie Information Plugin for WordPress
CVE-2023-6700
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 5 February 2024
What is CVE-2023-6700?
The Free GDPR Consent Solution plugin for WordPress is at risk due to a vulnerability that allows authenticated users to make arbitrary updates to site options. This issue arises from a lack of capability checking on the AJAX request handler. Attackers with subscriber-level access or higher can exploit this vulnerability to alter site configurations, potentially creating administrator accounts and compromising site integrity. Users of versions up to 2.0.22 are advised to update their plugin to mitigate these risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cookie Information | Free GDPR Consent Solution * <= 2.0.22
References
EPSS Score
24% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved