CVE-2024-11724: Cookie Consent for WP – Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) <= 3.6.5 - Missing Authorization to Authenticated (Subscriber+) Whitelist Script
The Cookie Consent for WP – Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wplscriptsave AJAX action in all versions up to, and including, 3.6.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to whitelist scripts.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11724?
CVE-2024-11724 has a medium severity rating due to its potential for unauthorized modification of data.
How do I fix CVE-2024-11724?
To fix CVE-2024-11724, upgrade the Cookie Consent for WP plugin to version 3.6.6 or later.
What software is affected by CVE-2024-11724?
CVE-2024-11724 affects the Cookie Consent for WP plugin for WordPress, specifically versions up to 3.6.5.
What type of attack does CVE-2024-11724 enable?
CVE-2024-11724 enables unauthorized data modification due to the lack of a capability check in the wpl_script_save AJAX action.
Is there a known exploit for CVE-2024-11724?
As of now, there are no publicly disclosed exploits specifically targeting CVE-2024-11724.