GHSA-crh8-vq8f-q88qMediumCVSS 4.3
The GDPR Cookie Compliance WordPress plugin before 5.1.0 expires the visitor's cookies from an...
🔗 CVE IDs covered (1)
📋 Description
The GDPR Cookie Compliance WordPress plugin before 5.1.0 expires the visitor's cookies from an action that is reachable without authentication and performs no request-origin check, allowing an attacker to log any user out and delete the site's cookies by luring them to a crafted link.