Description
WordPress Plugin Cookie Information-Free GDPR Consent Solution is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently edit arbitrary site options which can be used to create administrator accounts. WordPress Plugin Cookie Information-Free GDPR Consent Solution version 2.0.22 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.0.23 or latest
References
Related Vulnerabilities
WordPress Plugin Customer Service Software & Support Ticket System Cross-Site Scripting (5.5.1)
Drupal Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-9015)
Plone CMS Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-5487)
WordPress Plugin PHPFreeChat 'url' Parameter Cross-Site Scripting (0.2.8)