CyberRota Analysis
AI-GeneratedThe Cookie Consent plugin for WordPress versions prior to 0.0.10 has a vulnerability that allows any authenticated user, including subscribers, to overwrite the geolocation service license key due to improper enforcement of administrator-only access on the REST route. This could lead to unauthorized changes in the consent banner targeting, potentially disrupting compliance with privacy regulations. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The Cookie Consent WordPress plugin before 0.0.10 does not correctly enforce its intended administrator-only capability check on the REST route that stores its geolocation service license key, so the route falls back to an authentication-only gate, allowing any authenticated user such as a subscriber to overwrite the stored key and disrupt the Cookie Consent WordPress plugin before 0.0.10's geolocation-based consent banner targeting.