PT-2024-15057 · WordPress · Cookie Information

Lucio Sá

·

Published

2024-02-02

·

Updated

2024-02-09

·

CVE-2023-6700

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cookie Information | Free GDPR Consent Solution plugin for WordPress versions up to, and including, 2.0.22
Description The issue is related to a missing capability check on the AJAX request handler, allowing authenticated attackers with subscriber-level access or higher to edit arbitrary site options. This can be used to create administrator accounts. It is estimated that around 100,000 WordPress sites are potentially affected.
Recommendations For versions up to, and including, 2.0.22, update to a version higher than 2.0.22 to resolve the issue. As a temporary workaround, consider restricting access to the AJAX request handler until a patch is available. Additionally, monitor site options for any unauthorized changes and restrict subscriber-level access to minimize the risk of exploitation.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2023-6700

Affected Products

Cookie Information