WordPress Plugin Vulnerabilities

GDPR Cookie Compliance < 5.1.0 - Cookie Deletion and Forced Logout via CSRF

Description

The plugin expires the visitor's cookies from an action that is reachable without authentication and performs no request-origin check, allowing an attacker to log any user out and delete the site's cookies by luring them to a crafted link.

Proof of Concept

Affects Plugins

References

Classification

Miscellaneous

Original Researcher
Abdullah Kareem (cyberkareem)
Submitter
Abdullah Kareem (cyberkareem)
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-07-27 (about 9 days ago)
Added
2026-07-27 (about 8 days ago)
Last Updated
2026-07-27 (about 8 days ago)

Other