Webtoffee GDPR Cookie Consent WordPress Plugin Cross-Site Request Forgery Vulnerability

Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Webtoffee GDPR Cookie Consent WordPress plugin, affecting versions prior to 2.6.1. The vulnerability arises because the plugin lacks CSRF protection in certain bulk action features. This oversight could enable attackers to manipulate logged-in administrators into performing unintended actions, such as removing visit logs.

Impact

Exploitation of this vulnerability could lead to unauthorized deletion of visit logs by exploiting the absence of CSRF checks in bulk actions.

Remediation

Users are advised to update the Webtoffee GDPR Cookie Consent WordPress plugin to version 2.6.1 or later.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
6.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.