CVE-2024-5607

The GDPR CCPA Compliance & Cookie Consent Banner plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions named ajaxUpdateSettings() in all versions up to, and including, 2.7.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify the plugin's settings, update page content, send arbitrary emails and inject malicious web scripts.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ninjateam:gdpr_ccpa_compliance_\&_cookie_consent_banner:*:*:*:*:*:wordpress:*:*

History

29 Oct 2024, 20:08

Type Values Removed Values Added
CWE CWE-862
CPE cpe:2.3:a:ninjateam:gdpr_ccpa_compliance_\&_cookie_consent_banner:*:*:*:*:*:wordpress:*:*
First Time Ninjateam gdpr Ccpa Compliance \& Cookie Consent Banner
Ninjateam
References () https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3097680%40ninja-gdpr-compliance&new=3097680%40ninja-gdpr-compliance&sfp_email=&sfph_mail= - () https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3097680%40ninja-gdpr-compliance&new=3097680%40ninja-gdpr-compliance&sfp_email=&sfph_mail= - Patch
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/b8f870a6-26a5-4f98-9bd6-12736c561265?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/b8f870a6-26a5-4f98-9bd6-12736c561265?source=cve - Third Party Advisory

07 Jun 2024, 14:56

Type Values Removed Values Added
Summary
  • (es) El complemento GDPR CCPA Compliance & Cookie Consent Banner para WordPress es vulnerable a modificaciones no autorizadas de datos debido a una falta de verificación de capacidad en varias funciones denominadas ajaxUpdateSettings() en todas las versiones hasta la 2.7.0 incluida. Esto hace posible que atacantes autenticados, con acceso de nivel de suscriptor y superior, modifiquen la configuración del complemento, actualicen el contenido de la página, envíen correos electrónicos arbitrarios e inyecten scripts web maliciosos.

07 Jun 2024, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-07 03:15

Updated : 2024-10-29 20:08


NVD link : CVE-2024-5607

Mitre link : CVE-2024-5607

CVE.ORG link : CVE-2024-5607


JSON object : View

Products Affected

ninjateam

  • gdpr_ccpa_compliance_\&_cookie_consent_banner
CWE
CWE-862

Missing Authorization