CVE-2025-51529 is an Incorrect Access Control vulnerability affecting the jonkastonka Cookies and Content Security Policy plugin up to version 2.29. Specifically, the AJAX endpoint functionality allows unauthenticated attackers to trigger unlimited database write operations to the wp_ajax_nopriv_cacsp_insert_consent_data endpoint, leading to a denial of service due to database resource exhaustion. This vulnerability has a CVSS score of 5.3 (Medium), indicating it can be exploited remotely with low attack complexity and no user interaction, potentially causing a denial of service. While it has a low impact on confidentiality and integrity, its primary threat is resource exhaustion. Currently, there is no evidence of active exploitation, nor is exploit code available in Metasploit, Nuclei, or ExploitDB. The vulnerability has received minimal community discussion and media coverage, suggesting a low level of public awareness or immediate threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.29CPE matchmatch criteria | cpe:2.3:a:followmedarling:cookies_and_content_security_policy:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.