The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting visit logs via CSRF attacks
History

Thu, 12 Jun 2025 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Webtoffee
Webtoffee gdpr Cookie Consent
Weaknesses CWE-352
CPEs cpe:2.3:a:webtoffee:gdpr_cookie_consent:*:*:*:*:*:wordpress:*:*
Vendors & Products Webtoffee
Webtoffee gdpr Cookie Consent

Sat, 17 May 2025 04:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 15 May 2025 20:15:00 +0000

Type Values Removed Values Added
Description The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting visit logs via CSRF attacks
Title GDPR Cookie Consent <= 2.6.0 - Bulk Delete via CSRF
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2025-05-15T20:07:14.783Z

Updated: 2025-05-17T03:20:31.865Z

Reserved: 2024-08-28T19:41:24.638Z

Link: CVE-2024-8286

cve-icon Vulnrichment

Updated: 2025-05-17T03:20:09.007Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-15T20:15:58.417

Modified: 2025-06-12T15:34:28.220

Link: CVE-2024-8286

cve-icon Redhat

No data.