CyberRota Analysis
AI-GeneratedThe WPLP Cookie Consent plugin for WordPress versions prior to 4.4.2 is vulnerable due to the absence of authorization and CSRF checks when managing visitor consent states, enabling unauthenticated attackers to modify site-wide options with arbitrary data on each front-end page load. This flaw poses a risk of unauthorized changes to site configurations, potentially leading to further exploitation or data integrity issues. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this vulnerability.
Original NVD Description
The WPLP Cookie Consent WordPress plugin before 4.4.2 does not have any authorisation or CSRF checks when storing visitor consent state, and the code that does so runs on every front-end page load, allowing unauthenticated attackers to overwrite a site-wide option with arbitrary data.