Unauthorized Data Modification in WP Cookie Consent Plugin for WordPress
CVE-2025-14061

5.3MEDIUM

What is CVE-2025-14061?

The WP Cookie Consent plugin for WordPress contains a security flaw in the gdpr_delete_policy_data function. This vulnerability allows unauthorized users to modify or permanently delete posts, pages, attachments, and various post types by exploiting the lack of a capability check. All versions up to and including version 4.0.7 are affected. As a result, attackers can manipulate crucial site data, leading to potential information loss and compliance issues with GDPR and other data protection regulations.

Affected Version(s)

Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Consent * <= 4.0.7

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Angus Girvan
.
CVE-2025-14061 : Unauthorized Data Modification in WP Cookie Consent Plugin for WordPress