The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.5.6. This is due to missing or incorrect nonce validation on the process_delete function in class-DNSMPD.php. This makes it possible for unauthenticated attackers to delete GDPR data requests via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
History

Thu, 16 Jan 2025 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Complianz
Complianz complianz
Weaknesses CWE-352
CPEs cpe:2.3:a:complianz:complianz:*:*:*:*:*:wordpress:*:*
Vendors & Products Complianz
Complianz complianz

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-03-02T06:46:19.551Z

Updated: 2024-08-01T18:48:20.645Z

Reserved: 2024-02-16T19:46:30.767Z

Link: CVE-2024-1592

cve-icon Vulnrichment

Updated: 2024-08-01T18:48:20.645Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-02T07:15:46.207

Modified: 2025-01-16T18:44:36.740

Link: CVE-2024-1592

cve-icon Redhat

No data.