CVE-2023-4013: GDPR Cookie Compliance < 4.12.5 - License Update/Deactivation via CSRF
The GDPR Cookie Compliance (CCPA, DSGVO, Cookie Consent) WordPress plugin before 4.12.5 does not have proper CSRF checks when managing its license, which could allow attackers to make logged in admins update and deactivate the plugin's license via CSRF attacks
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-4013?
CVE-2023-4013 is a vulnerability in the GDPR Cookie Compliance (CCPA, DSGVO, Cookie Consent) WordPress plugin before version 4.12.5 that allows attackers to update and deactivate the plugin's license via CSRF attacks.
What is the severity of CVE-2023-4013?
The severity of CVE-2023-4013 is medium with a CVSS score of 6.5.
How does CVE-2023-4013 affect the GDPR Cookie Compliance plugin?
CVE-2023-4013 affects the GDPR Cookie Compliance plugin before version 4.12.5 by not having proper CSRF checks when managing its license.
How can I fix CVE-2023-4013?
To fix CVE-2023-4013, you should update the GDPR Cookie Compliance plugin to version 4.12.5 or higher.
What is the CWE of CVE-2023-4013?
The CWE of CVE-2023-4013 is CWE-352.