Medium severity5.4NVD Advisory· Published Jun 7, 2023· Updated Jun 17, 2026
CVE-2019-25143
CVE-2019-25143
Description
The GDPR Cookie Compliance plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the gdpr_cookie_compliance_reset_settings AJAX action in versions up to, and including, 4.0.2. This makes it possible for authenticated attackers to reset all of the settings.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2cpe:2.3:a:mooveagency:gdpr_cookie_compliance:*:*:*:*:*:wordpress:*:*+ 1 more
- cpe:2.3:a:mooveagency:gdpr_cookie_compliance:*:*:*:*:*:wordpress:*:*range: <4.0.3
- (no CPE)range: <=4.0.2
Patches
Vulnerability mechanics
References
4- blog.nintechnet.com/wordpress-gdpr-cookie-compliance-plugin-fixed-authenticated-settings-deletion-vulnerability/nvdExploit
- wpscan.com/vulnerability/5ac51325-a7f5-4d38-9b41-61855206083dnvdThird Party Advisory
- www.acunetix.com/vulnerabilities/web/wordpress-plugin-gdpr-cookie-compliance-security-bypass-4-0-2/nvdThird Party Advisory
- www.wordfence.com/threat-intel/vulnerabilities/id/9116d719-f536-4b8a-9e73-9a8a922f8a35nvdBroken LinkThird Party Advisory
News mentions
0No linked articles in our index yet.