Medium severity5.4NVD Advisory· Published Jun 7, 2023· Updated Apr 8, 2026
CVE-2019-25143
CVE-2019-25143
Description
The GDPR Cookie Compliance plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the gdpr_cookie_compliance_reset_settings AJAX action in versions up to, and including, 4.0.2. This makes it possible for authenticated attackers to reset all of the settings.
Affected products
1- cpe:2.3:a:mooveagency:gdpr_cookie_compliance:*:*:*:*:*:wordpress:*:*Range: <4.0.3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- blog.nintechnet.com/wordpress-gdpr-cookie-compliance-plugin-fixed-authenticated-settings-deletion-vulnerability/nvdExploit
- wpscan.com/vulnerability/5ac51325-a7f5-4d38-9b41-61855206083dnvdThird Party Advisory
- www.acunetix.com/vulnerabilities/web/wordpress-plugin-gdpr-cookie-compliance-security-bypass-4-0-2/nvdThird Party Advisory
- www.wordfence.com/threat-intel/vulnerabilities/id/9116d719-f536-4b8a-9e73-9a8a922f8a35nvdBroken LinkThird Party Advisory
News mentions
0No linked articles in our index yet.