HomeSecurityGDPR Cookie plugins expose Wordpress websites to hacking attacks!

GDPR Cookie plugins expose WordPress websites to hacking attacks!

Critical security issues caused by improper access controls in a WordPress plugin designed for GDPR cookie compliance have been identified and resolved . Unfortunately, hundreds of thousands of websites may still be vulnerable to attack.

The GDPR Cookie Consent plugin, offered by developer Cookie Law Info via WebToffee, is designed to ensure that websites comply with the EU General Data Protection (GDPR). Specifically, it involves obtaining cookie consent from visitors, creating a privacy & cookies policy page, and enabling banners that demonstrate compliance.

GDPR Cookies

The plugin has more than 700,000 active installations according to the WordPress library.

The news was born on January 28, 2019, when NinTechNet researcher Jerome Bruandet discovered a vulnerability affecting GDPR Cookie Consent version 1.8.2 and earlier. Essentially, it is a critical issue caused by failed capability checks, leading to validated cross-site scripting (XSS) and potential privilege escalation.

How was the error caused?

It all boils down to a vulnerable AJAX endpoint where failure to execute checks meant that three actions were exposed: get_policy_pageid, autosave_contant_data, and save_contentdata.

According to WordPress, "because the AJAX endpoint was intended to be accessible only to administrators, the vulnerability allows subscriber users to perform a number of actions that could compromise the security of the site."

WordPress

While get_policy_pageid only provides the post ID of a cookie policy page and therefore does not cause much damage, the exposure of autosave_contant_data – (spelling error in the code) – a function intended to set the default content on the policy preview page means that this page could be injected with XSS payloads.

Thus, malicious payloads are executed when users visit http:///cli-policy-preview/

Additionally, save_contentdata is intended for use in creating or updating the post used for the policy page, and so the exposure could allow attackers to change the content of the post in various ways.

Using this action may result in the deletion of material or the loading of malicious content, including "formatted text, local or remote images, as well as hyperlinks and passwords."

GDPR Cookie plugin users are advised to make sure they are using the latest version of the software, 1.8.3, to stay protected. As of this writing, 64.5% of users have been updated – with thousands of websites still exposed.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS