QID 730800
Date Published: 2023-05-18
QID 730800: WordPress Plugin GDPR Cookie Consent Improper Access Control Vulnerability
The CookieYes GDPR Cookie Consent plugin will assist you in making your website GDPR (RGPD, DSVGO) compliant by adding a cookie banner to your site.
GDPR Cookie Consent (cookie-law-info) 1.8.2 and below plugin for WordPress, allows authenticated stored XSS and privilege escalation.
Affected Versions:
GDPR Cookie Consent WordPress plugin versions prior to 1.8.3
QID Detection Logic(Unauthenticated):
This unauthenticated detection depends on the BlindElephant engine to detect the vulnerable version of the GDPR Cookie Consent plugin.
Successful exploitation of this vulnerability may allow an authenticated user with low privileges to either change the status of any post/page from published to draft, removing them from the frontend of the blog or put a payload in the content of one of them, leading to Stored Cross-Site Scripting (XSS) issues.
- GDPR Cookie Consent Plugin Release Notes -
wordpress.org/plugins/cookie-law-info/#developers
CVEs related to QID 730800
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GDPR Cookie Consent Plugin Release Notes |
|