Arbitrary Option Update Vulnerability in Cookie Information Plugin for WordPress
CVE-2023-6700

8.8HIGH

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
5 February 2024

Summary

The Free GDPR Consent Solution plugin for WordPress is at risk due to a vulnerability that allows authenticated users to make arbitrary updates to site options. This issue arises from a lack of capability checking on the AJAX request handler. Attackers with subscriber-level access or higher can exploit this vulnerability to alter site configurations, potentially creating administrator accounts and compromising site integrity. Users of versions up to 2.0.22 are advised to update their plugin to mitigate these risks.

Affected Version(s)

Cookie Information | Free GDPR Consent Solution * <= 2.0.22

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lucio Sá
.