Webtoffee GDPR Cookie Consent WordPress Plugin Cross-Site Request Forgery Vulnerability
Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Webtoffee GDPR Cookie Consent WordPress plugin, affecting versions prior to 2.6.1. The vulnerability arises because the plugin lacks CSRF protection in certain bulk action features. This oversight could enable attackers to manipulate logged-in administrators into performing unintended actions, such as removing visit logs.
Impact
Exploitation of this vulnerability could lead to unauthorized deletion of visit logs by exploiting the absence of CSRF checks in bulk actions.
Remediation
Users are advised to update the Webtoffee GDPR Cookie Consent WordPress plugin to version 2.6.1 or later.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
