CVE · High

CVE-2022-3911 — iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more [iubenda-cookie-law-solution] < 3.3.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-3911 iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more [iubenda-cookie-law-solution] < 3.3.3 Cross-Site Request Forgery (CSRF) High 8.8 < 3.3.3 3.3.3 2022-12-12

CVE-2022-3911

The iubenda plugin for WordPress up to version 3.3.2 contains a privilege escalation vulnerability caused by insufficient verification checks in multiple functions including 'process_actions' and 'ajax_save_options'. This flaw allows users with subscriber-level access to execute AJAX actions restricted to higher-privileged users, such as modifying plugin settings and escalating their own account permissions.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.