Input validation vulnerability in Complianz – GDPR/CCPA Cookie Consent 6.4.4

The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress has a security vulnerability in versions up to, and including, 6.4.4. This vulnerability allows unauthenticated attackers to delete the compliance cookie banner without permission. This is because the plugin does not properly validate nonce on the cmplz_delete_cookiebanner function. Attackers can take advantage of this situation by tricking a site administrator into clicking on a malicious link or performing a similar action.

Detected in:

Complianz – GDPR/CCPA Cookie Consent fixed vulnerable versions: >= * <= 6.4.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.