WordPress Plugin Vulnerabilities

Cookie Consent < 0.0.10 - Subscriber+ MaxMind License Key Update

Description

The plugin does not correctly enforce its intended administrator-only capability check on the REST route that stores its geolocation service license key, so the route falls back to an authentication-only gate, allowing any authenticated user such as a subscriber to overwrite the stored key and disrupt the plugin's geolocation-based consent banner targeting.

Proof of Concept

Affects Plugins

Fixed in 0.0.10

References

Classification

Type
INCORRECT AUTHORISATION
CWE

Miscellaneous

Original Researcher
Erwan LR (WPScan)
Submitter
Erwan LR (WPScan)
Verified
Yes

Timeline

Publicly Published
2026-08-10 (about 2 days ago)
Added
2026-08-10 (about 1 day ago)
Last Updated
2026-08-10 (about 1 day ago)

Other