WP GDPR Compliance <= 1.4.2 - Arbitrary Options Update and Action Calling

2018-11-08 00:00
Adrian Mörchen

Strategic Overview

Status
Patched in 1.4.3
Affected Version< 1.4.3
CVSS9.8Critical
CVECVE-2018-19207
View all Cookie Information | Free GDPR Consent Solution vulnerabilities

Vulnerability Overview

The WP GDPR Compliance plugin for WordPress is vulnerability to arbitrary options updates and action calling in versions up to, and including 1.4.2 due to insufficient capability checking on the wpgdprc_process_action AJAX action. This missing it possible for unauthenticated attackers to trigger the AJAX action and make updates to the sites options that can be used to create administrative user accounts.

Technical Analysis

REMEDIATION: Update to version 1.4.3, or a newer patched version --- IDENTIFIER: CWE-94 (Improper Control of Generation of Code ('Code Injection')) The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C