Description
WordPress Plugin Cookie Information-Free GDPR Consent Solution is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently edit arbitrary site options which can be used to create administrator accounts. WordPress Plugin Cookie Information-Free GDPR Consent Solution version 2.0.22 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.0.23 or latest
References
Related Vulnerabilities
WordPress Plugin Social Review includes Backdoor [Only if downloaded via the vendor website] (1.0.8)
MySQL CVE-2016-0639 Vulnerability (CVE-2016-0639)
MySQL CVE-2018-2775 Vulnerability (CVE-2018-2775)
WordPress Plugin Anti-Malware Security and Brute-Force Firewall Cross-Site Scripting (4.15.49)
WordPress Plugin Fonts-Google Fonts Typography Cross-Site Scripting (3.0.2)