Stored Cross-Site Scripting in WP DSGVO Tools Plugin for WordPress
CVE-2021-4358
7.2HIGH
Summary
The WP DSGVO Tools (GDPR) plugin for WordPress suffers from a vulnerability due to insufficient input sanitization and output escaping. This flaw allows unauthenticated attackers to perform stored cross-site scripting (XSS) attacks by injecting arbitrary scripts through an unspecified parameter. When users access affected pages, the injected scripts execute, potentially compromising user data and website integrity. The vulnerability impacts versions up to and including 3.1.23, highlighting the importance of timely updates and security best practices for WordPress users.
Affected Version(s)
WP DSGVO Tools (GDPR) * < 3.1.24
References
CVSS V3.1
Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jerome Bruandet