Stored Cross-Site Scripting Vulnerability Affects Cookie Notice & Compliance Plugin
CVE-2022-3399

4.4MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
16 August 2024

Summary

The Cookie Notice & Compliance for GDPR / CCPA plugin for WordPress contains a vulnerability that allows for Stored Cross-Site Scripting through the 'cookie_notice_options[refuse_code_head]' parameter. This flaw arises from inadequate input sanitization and output escaping practices, enabling authenticated attackers with administrative privileges to inject malicious web scripts. These scripts may execute whenever a user accesses the affected /wp-admin/admin.php?page=cookie-notice page. The vulnerability is specifically present in multi-site installations and those where unfiltered_html has been disabled, posing a significant risk to the integrity and security of affected websites.

Affected Version(s)

Cookie Notice & Compliance for GDPR / CCPA * <= 2.4.17.1

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

c3p0d4y
.