CVE · Medium

CVE-2023-4013 — GDPR Cookie Compliance – Cookie Banner, Cookie Consent, Cookie Notice for CCPA, EU Cookie Law [gdpr-cookie-compliance] < 4.12.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-4013 GDPR Cookie Compliance – Cookie Banner, Cookie Consent, Cookie Notice for CCPA, EU Cookie Law [gdpr-cookie-compliance] < 4.12.5 Cross-Site Request Forgery (CSRF) Medium 6.5 < 4.12.5 4.12.5 2023-08-07

CVE-2023-4013

The GDPR Cookie Compliance plugin for WordPress through version 4.12.4 contains a Cross-Site Request Forgery vulnerability stemming from inadequate nonce verification in the /views/moove/admin/settings/licence.php file. Unauthenticated attackers can exploit this flaw to modify or disable the plugin's license key if they can persuade an administrator to click a malicious link. The vulnerability affects versions up to 4.12.4 and is patched in version 4.12.5.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.