CyberRota Analysis
AI-GeneratedThe WPLP Cookie Consent plugin for WordPress prior to version 4.4.2 is vulnerable due to the lack of nonce and capability checks on its AJAX actions, enabling any authenticated user, including subscribers, to manipulate the plugin's settings. This vulnerability allows unauthorized access to sensitive scan data and the ability to overwrite the plugin's configuration, potentially compromising site integrity. WordPress administrators using this plugin should prioritize updating to version 4.4.2 or later to mitigate these risks.
Original NVD Description
The WPLP Cookie Consent WordPress plugin before 4.4.2 does not perform nonce or capability checks on several of its settings AJAX actions, allowing any authenticated user, such as a subscriber, to read and destroy scan data belonging to the administrator and to overwrite the WPLP Cookie Consent WordPress plugin before 4.4.2's stored configuration.