CVE-2023-4013Cross-Site Request Forgery in Gdpr Cookie Compliance

Severity
6.5MEDIUMNVD
EPSS
0.2%
top 62.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 30

Description

The GDPR Cookie Compliance (CCPA, DSGVO, Cookie Consent) WordPress plugin before 4.12.5 does not have proper CSRF checks when managing its license, which could allow attackers to make logged in admins update and deactivate the plugin's license via CSRF attacks

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages1 packages

🔴Vulnerability Details

2
CVEList
GDPR Cookie Compliance < 4.12.5 - License Update/Deactivation via CSRF2023-08-30
GHSA
GHSA-jwv3-p6w3-6prm: The GDPR Cookie Compliance (CCPA, DSGVO, Cookie Consent) WordPress plugin before 42023-08-30
CVE-2023-4013 — Cross-Site Request Forgery | cvebase