WebToffee Cookie Consent < 3.5.3 - Consent Log Disclosure/Deletion, Page Creation & License Deactivation via Unprotected REST Routes
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 6.5epss 0.3%
exploitation probability
0.3%top 78% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The webtoffee-cookie-consent WordPress plugin before 3.5.3 does not perform authorization checks on several of its REST API routes, allowing unauthenticated attackers to export and delete stored visitor consent records, create posts, and modify the webtoffee-cookie-consent WordPress plugin before 3.5.3's licensing state.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Affected products
Unknown · webtoffee-cookie-consentpublic PoCs found — 1
cve_referencewpscan.com/vulnerability/a591c79d-5db7-4716-8b6c-004b1195edf7/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.