CVE-2025-24591

M

issing Authorization vulnerability in NinjaTeam GDPR CCPA Compliance Support allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects GDPR CCPA Compliance Support: from n/a through 2.7.1.

Configurations

Configuration 1 (hide)

cpe:2.3:a:ninjateam:gdpr_ccpa_compliance_\&_cookie_consent_banner:*:*:*:*:*:wordpress:*:*

History

10 Mar 2025, 18:22

Type Values Removed Values Added
References () https://patchstack.com/database/wordpress/plugin/ninja-gdpr-compliance/vulnerability/wordpress-gdpr-ccpa-compliance-cookie-consent-banner-plugin-2-7-1-broken-access-control-vulnerability?_s_id=cve - () https://patchstack.com/database/wordpress/plugin/ninja-gdpr-compliance/vulnerability/wordpress-gdpr-ccpa-compliance-cookie-consent-banner-plugin-2-7-1-broken-access-control-vulnerability?_s_id=cve - Third Party Advisory
CPE cpe:2.3:a:ninjateam:gdpr_ccpa_compliance_\&_cookie_consent_banner:*:*:*:*:*:wordpress:*:*
First Time Ninjateam
Ninjateam gdpr Ccpa Compliance \& Cookie Consent Banner
Summary
  • (es) La vulnerabilidad de falta de autorización en NinjaTeam GDPR CCPA Compliance Support permite explotar niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta al soporte de cumplimiento de GDPR CCPA: desde n/d hasta 2.7.1.

24 Jan 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-24 18:15

Updated : 2025-03-10 18:22


NVD link : CVE-2025-24591

Mitre link : CVE-2025-24591

CVE.ORG link : CVE-2025-24591


JSON object : View

CWE
CWE-862

Missing Authorization