CVE-2024-3599: WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) <= 3.0.2 - Missing Authorization to Unauthenticated Arbitrary Post Deletion
The WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the gdprpolicyprocessdelete() function in all versions up to, and including, 3.0.2. This makes it possible for unauthenticated attackers to delete arbitrary posts.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3599?
CVE-2024-3599 is considered a critical vulnerability due to its potential for unauthorized data loss by unauthenticated attackers.
How do I fix CVE-2024-3599?
To fix CVE-2024-3599, update the WP Cookie Consent plugin to version 3.1.0 or later immediately.
Who is affected by CVE-2024-3599?
CVE-2024-3599 affects all versions of the WP Cookie Consent plugin up to and including 3.0.2.
What type of vulnerability is CVE-2024-3599?
CVE-2024-3599 is a vulnerability that allows unauthorized deletion of data due to a missing capability check.
Can CVE-2024-3599 be exploited remotely?
Yes, CVE-2024-3599 can be exploited remotely by unauthenticated attackers.