The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.5.6. This is due to missing or incorrect nonce validation on the process_delete function in class-DNSMPD.php. This makes it possible for unauthenticated attackers to delete GDPR data requests via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
We have discovered 49,892 live websites that are affected by CVE-2024-1592.
| Product | |
| Category | Cookie compliance |
| Vulnerable Domains | 49,892 live websites (13% of Complianz install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 64 versions ( 62% of all versions) |
| 3,043 websites | |
| 15,675 websites | |
| 5,303 websites | |
| 5,172 websites | |
| 4,942 websites | |
| 2,743 websites | |
| 1,344 websites | |
| 1,230 websites | |
| 1,177 websites | |
| 1,130 websites |
| .com | 13,339 websites |
| .de | 11,852 websites |
| .it | 3,868 websites |
| .cz | 2,529 websites |
| .fr | 2,289 websites |
| .es | 2,205 websites |
| .at | 1,333 websites |
| .nl | 1,017 websites |
| .org | 940 websites |
| .co.uk | 808 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *********.com | *,*** | ||
| ******.com | *,*** | ||
| *****.com | **,*** | ||
| ****.edu | **,*** | ||
| *****.de | **,*** | ||
| *********.com | **,*** | ||
| ****************.com | **,*** | ||
| *******.com | **,*** | ||
| ********.com | **,*** | ||
| ************.com | **,*** |