CVE-2026-13389
Received Received - Intake

Unauthenticated REST API Access in WebToffee Cookie Consent Plugin

Vulnerability report for CVE-2026-13389, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-02

Last updated on: 2026-08-02

Assigner: WPScan

Description

The webtoffee-cookie-consent WordPress plugin before 3.5.3 does not perform authorization checks on several of its REST API routes, allowing unauthenticated attackers to export and delete stored visitor consent records, create posts, and modify the webtoffee-cookie-consent WordPress plugin before 3.5.3's licensing state.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-02
Last Modified
2026-08-02
Generated
2026-08-02
AI Q&A
2026-08-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
webtoffee webtoffee-cookie-consent to 3.5.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The vulnerability in the webtoffee-cookie-consent WordPress plugin before version 3.5.3 allows unauthenticated attackers to perform unauthorized actions via REST API routes. These actions include exporting and deleting visitor consent records, creating posts, and modifying the plugin's licensing state without proper authorization checks.

Detection Guidance

Check for unauthorized access to REST API routes in the webtoffee-cookie-consent plugin. Inspect logs for unusual POST, GET, or DELETE requests to endpoints like /wp-json/webtoffee/v1/export, /wp-json/webtoffee/v1/delete, or /wp-json/webtoffee/v1/create. Verify plugin version is 3.5.3 or higher.

Impact Analysis

This vulnerability can lead to unauthorized access to sensitive data, such as visitor consent records. Attackers could delete or export this data, create unauthorized posts on your site, or alter the plugin's licensing, potentially disrupting its functionality and compromising user trust.

Compliance Impact

This vulnerability can impact compliance with GDPR and other privacy regulations by allowing unauthorized access to or deletion of visitor consent records. GDPR requires proper handling of consent data, and unauthorized modifications or deletions could result in non-compliance and potential legal consequences.

Mitigation Strategies

Update the webtoffee-cookie-consent plugin to version 3.5.3 or later immediately. Disable REST API routes if not required. Review logs for signs of exploitation and remove unauthorized posts or records. Implement strict access controls for WordPress admin and API endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-13389. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart