Description
WordPress Plugin Cookie Information-Free GDPR Consent Solution is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently edit arbitrary site options which can be used to create administrator accounts. WordPress Plugin Cookie Information-Free GDPR Consent Solution version 2.0.22 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.0.23 or latest
References
Related Vulnerabilities
WordPress Plugin Job Manager Cross-Site Scripting (0.7.25)
Oracle JRE CVE-2013-3744 Vulnerability (CVE-2013-3744)
XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-50723)
PHP Other Vulnerability (CVE-2007-1900)
WordPress Plugin WordPress Download Manager Cross-Site Request Forgery (2.8.99)