The GDPR Cookie Compliance WordPress plugin before 5.1.0 expires the visitor's cookies from an action that is reachable without authentication and performs no request-origin check, allowing an attacker to log any user out and delete the site's cookies by luring them to a crafted link.
https://wpscan.com/vulnerability/d9511e8a-be67-4c39-b947-7931b5569ffb/