VYPR
Medium severity5.3NVD Advisory· Published Dec 16, 2025· Updated Apr 27, 2026

CVE-2025-66133

CVE-2025-66133

Description

Missing Authorization vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent gdpr-cookie-consent allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through <= 4.0.7.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Missing authorization in WP Cookie Notice plugin up to version 4.0.7 allows attackers to bypass access controls and perform privileged actions.

What the vulnerability is: The WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin (gdpr-cookie-consent) versions up to 4.0.7 contain a missing authorization vulnerability. The plugin fails to properly enforce access controls on certain functions, leading to a broken access control issue [1].

How it is exploited: An attacker with no or low privileges can exploit the missing authorization checks to access higher privileged actions. The vulnerability arises from missing capability or nonce token checks in the plugin's code, allowing an unprivileged user to perform actions intended for administrators [1].

Impact: Successful exploitation may allow an attacker to modify or view sensitive configuration settings related to cookie consent, potentially affecting website compliance with GDPR, CCPA, and ePrivacy regulations. The vulnerability has been noted in mass-exploit campaigns, though its severity is considered low [1].

Mitigation: Users are strongly advised to update to version 4.0.8 or later, which addresses the missing authorization. Patchstack users can enable auto-updates for the plugin to ensure timely patching [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.