What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in Cookie Information A/S WP GDPR Compliance.This issue affects WP GDPR Compliance: from n/a through 2.0.23.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in Cookie Information A/S WP GDPR Compliance.This issue affects WP GDPR Compliance: from n/a through 2.0.23.
Explanation of Vulnerability in Simple Terms
WP GDPR Compliance versions up to 2.0.23 contain a cross-site request forgery (CSRF) vulnerability that allows attackers to perform unauthorized actions on behalf of site administrators. An attacker can craft a malicious link or page that, when visited by an admin, triggers unwanted changes to plugin settings or site configuration. The vulnerability requires no special privileges but does require the admin to click a link or visit a page controlled by the attacker.
What an attacker can do
Trick a site admin into performing unauthorized actions like changing plugin settings or modifying site configuration.
Potential impact on your site
Attackers can alter GDPR compliance settings or other plugin configurations without your knowledge or consent.
Conditions required to exploit
Site admin must click a malicious link or visit an attacker-controlled page while logged in.
Key dates
External resources
Related vulnerabilities