WPLP Cookie Consent 4.0.2 - 4.4.1 - Subscriber+ Cookie Scan Schedule Disclosure via gcc_get_schedule_scan
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 4.3epss 0.3%
exploitation probability
0.3%top 83% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The WPLP Cookie Consent WordPress plugin before 4.4.2 does not perform nonce or capability checks on one of its cookie scanner AJAX actions, allowing any authenticated user, such as a subscriber, to read back the automated scan schedule the administrator configured.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Affected products
Unknown · WPLP Cookie Consentpublic PoCs found — 1
cve_referencewpscan.com/vulnerability/412f604b-ee33-42b6-8a39-00f7564d4e2b/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.