Missing Authorization Flaw in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent
CVE-2025-66075

4.2MEDIUM

What is CVE-2025-66075?

A missing authorization vulnerability exists in the WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin that may allow unauthorized users to exploit improperly configured access control settings. This flaw affects versions up to 4.0.3 of the plugin, potentially leading to exposure of sensitive data or unauthorized actions by attackers.

Affected Version(s)

WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= n/a

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Legion Hunter | Patchstack Bug Bounty Program
.
CVE-2025-66075 : Missing Authorization Flaw in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent