Gtbabel <= 6.6.8 - Unauthenticated Cookie Stealing
2025-02-17 00:00
Hassan Khan Yusufzai - Splint3r7Strategic Overview
Vulnerability Overview
The Gtbabel plugin for WordPress is vulnerable to cookie stealing in all versions up to, and including, 6.6.8. This is due to the plugin transmitting cookie data via a URL. This makes it possible for unauthenticated attackers to steal admin cookies which may make privilege escalation possible, if they can successfully trick in administrator into clicking a link.
Technical Analysis
REMEDIATION: Update to version 6.6.9, or a newer patched version --- IDENTIFIER: CWE-614 (Sensitive Cookie in HTTPS Session Without 'Secure' Attribute) The Secure attribute for sensitive cookies in HTTPS sessions is not set.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C