Vulnerability Description
The WordPress Real Cookie Banner: GDPR (DSGVO) & ePrivacy Cookie Consent WordPress plugin before 2.14.2 does not have CSRF checks in place when resetting its settings, allowing attackers to make a logged in admin reset them via a CSRF attack
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Devowl | Wordpress Real Cookie Banner | < 2.14.2 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/d9f28255-0026-4c42-9e67-d17b618c2285ExploitThird Party Advisory
- https://wpscan.com/vulnerability/d9f28255-0026-4c42-9e67-d17b618c2285ExploitThird Party Advisory
FAQ
What is CVE-2022-0445?
CVE-2022-0445 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The WordPress Real Cookie Banner: GDPR (DSGVO) & ePrivacy Cookie Consent WordPress plugin before 2.14.2 does not have CSRF checks in place when resetting its settings, allowing attackers to make a log...
How severe is CVE-2022-0445?
CVE-2022-0445 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-0445?
Check the references section above for vendor advisories and patch information. Affected products include: Devowl Wordpress Real Cookie Banner.