CVE Database /
CVE-2023-4013
CVE · Medium
CVE-2023-4013 — GDPR Cookie Compliance – Cookie Banner, Cookie Consent, Cookie Notice for CCPA, EU Cookie Law [gdpr-cookie-compliance] < 4.12.5
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2023-4013
|
GDPR Cookie Compliance – Cookie Banner, Cookie Consent, Cookie Notice for CCPA, EU Cookie Law [gdpr-cookie-compliance] < 4.12.5 |
Cross-Site Request Forgery (CSRF) |
Medium
6.5
|
< 4.12.5
|
4.12.5 |
2023-08-07 |
—
|
CVE-2023-4013
The GDPR Cookie Compliance plugin for WordPress through version 4.12.4 contains a Cross-Site Request Forgery vulnerability stemming from inadequate nonce verification in the /views/moove/admin/settings/licence.php file. Unauthenticated attackers can exploit this flaw to modify or disable the plugin's license key if they can persuade an administrator to click a malicious link. The vulnerability affects versions up to 4.12.4 and is patched in version 4.12.5.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings