EUCookieLaw <= 2.7.2 - Unauthenticated Arbitrary File Read

Strategic Overview

Status
Patched in 2.7.3
Affected PluginEUCookieLaw
Affected Version<= 2.7.2
CVSS5.9Medium
CVECVE-2025-3897
View all EUCookieLaw vulnerabilities

Vulnerability Overview

The EUCookieLaw plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.7.2 via the 'file_get_contents' function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The vulnerability can only be exploited if a caching plugin such as W3 Total Cache is installed and activated.

Technical Analysis

REMEDIATION: Update to version 2.7.3, or a newer patched version --- IDENTIFIER: CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')) The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C