Server-Side Request Forgery in Real Cookie Banner Plugin for WordPress
CVE-2025-12136

6.8MEDIUM

What is CVE-2025-12136?

The Real Cookie Banner plugin for WordPress contains a vulnerability that allows authenticated attackers with administrator access to exploit insufficient URL validation in its '/scanner/scan-without-login' REST API endpoint. This flaw enables attackers to send web requests to unspecified external locations through the application, potentially querying or modifying sensitive information within internal services by manipulating the 'url' parameter. This vulnerability poses a significant risk to websites using the plugin, as it can facilitate unauthorized access to backend resources.

Affected Version(s)

Real Cookie Banner: GDPR & ePrivacy Cookie Consent * <= 5.2.4

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

SpiderSec
.
CVE-2025-12136 : Server-Side Request Forgery in Real Cookie Banner Plugin for WordPress