Description
WordPress Plugin Cookie Information-Free GDPR Consent Solution is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently edit arbitrary site options which can be used to create administrator accounts. WordPress Plugin Cookie Information-Free GDPR Consent Solution version 2.0.22 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.0.23 or latest
References
Related Vulnerabilities
PHP Improper Check for Unusual or Exceptional Conditions Vulnerability (CVE-2017-11144)
b2evolution Credentials Management Errors Vulnerability (CVE-2016-9479)
Nginx Out-of-bounds Read Vulnerability (CVE-2023-27727)
MySQL CVE-2013-2395 Vulnerability (CVE-2013-2395)
WordPress Plugin DX-Contribute Cross-Site Request Forgery (1.2.0)