The WPLP Cookie Consent WordPress plugin before 4.4.2 does not perform nonce or capability checks on one of its cookie scanner AJAX actions, allowing any authenticated user, such as a subscriber, to read back the automated scan schedule the administrator configured.
https://wpscan.com/vulnerability/412f604b-ee33-42b6-8a39-00f7564d4e2b/