CVE-2025-11754: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-11754 is a Missing Authorization vulnerability in the GDPR Cookie Consent plugin for WordPress that allows unauthenticated attackers to access sensitive plugin settings via an unprotected REST API endpoint. All versions up to and including 4.1.2 are affected. The vulnerability was published on February 19, 2026, and carries a CVSS v3.1 base score of 7.5 (High) (Red Hat CVE, Wordfence).

Technical details

The root cause is a missing capability check (CWE-862) on the gdpr/v1/settings REST API endpoint exposed by the GDPR Cookie Consent plugin. Because no authentication or authorization is enforced on this endpoint, any unauthenticated network attacker can send a simple HTTP GET request to retrieve the full plugin settings object. The exposed data includes API tokens, email addresses, account IDs, and site keys, which are stored and returned without access control (Red Hat CVE, Wordfence).

Impact

Successful exploitation results in a high confidentiality impact — unauthenticated attackers can retrieve sensitive configuration data including API tokens, email addresses, account IDs, and site keys. Leaked API tokens or account credentials could enable further attacks against third-party services integrated with the plugin, potentially expanding the attack surface beyond the WordPress site itself. Integrity and availability are not directly affected by this vulnerability (Red Hat CVE).

Exploitability

No public proof-of-concept exploit code or active in-the-wild exploitation has been confirmed as of the available data. The EPSS score is approximately 0.04%, indicating a low current probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the unauthenticated, low-complexity nature of the attack (no privileges or user interaction required) makes it straightforward to exploit if a site is running a vulnerable version (Red Hat CVE, Wordfence).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the GDPR Cookie Consent plugin (versions ≤ 4.1.2) using tools like WPScan, Shodan, or by inspecting plugin directories and readme files exposed on the target site.
  2. Identify the vulnerable endpoint: Confirm the REST API endpoint gdpr/v1/settings is accessible by sending a test request to https://<target>/wp-json/gdpr/v1/settings.
  3. Send unauthenticated request: Issue an HTTP GET request to the endpoint without any authentication headers or cookies:
    GET /wp-json/gdpr/v1/settings HTTP/1.1
    Host: <target>
  4. Harvest sensitive data: Parse the JSON response to extract API tokens, email addresses, account IDs, and site keys returned by the plugin settings endpoint.
  5. Leverage extracted credentials: Use harvested API tokens or account credentials to access integrated third-party services (e.g., consent management platforms) or conduct further targeted attacks (Red Hat CVE, Wordfence).

Indicators of compromise

  • Network: Unusual or repeated unauthenticated HTTP GET requests to /wp-json/gdpr/v1/settings from external IP addresses, particularly in high volume or from scanning infrastructure.
  • Logs: WordPress access logs showing requests to the gdpr/v1/settings REST API endpoint from unauthenticated sources (no session cookie or Authorization header); look for HTTP 200 responses to these requests from unknown IPs.
  • Process/Behavior: No direct process-level IOCs expected, as exploitation is a passive data read; however, subsequent use of harvested API tokens in third-party service logs may indicate post-exploitation activity.

Mitigation and workarounds

Users should update the GDPR Cookie Consent plugin to a version beyond 4.1.2 that includes a fix for the missing capability check on the gdpr/v1/settings REST API endpoint. Until a patch is applied, site administrators can use a WordPress security plugin (e.g., Wordfence) to block unauthenticated access to the affected REST API route, or restrict REST API access to authenticated users via server-level configuration. Rotating any API tokens, site keys, and credentials stored in the plugin settings is strongly recommended if exploitation cannot be ruled out (Wordfence, Red Hat CVE).

Community reactions

Wordfence included CVE-2025-11754 in their weekly WordPress vulnerability report for February 16–22, 2026, flagging it as a notable unauthorized data access issue (Wordfence). The vulnerability was also picked up by security aggregators and social media accounts including RedPacketSecurity on Mastodon and TheHackerWire, indicating moderate community awareness. No major vendor statements or high-profile researcher commentary beyond standard disclosure coverage have been observed.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management