Stored Cross-Site Scripting Vulnerability Affects Cookie Notice & Compliance Plugin
CVE-2022-3399
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 16 August 2024
Summary
The Cookie Notice & Compliance for GDPR / CCPA plugin for WordPress contains a vulnerability that allows for Stored Cross-Site Scripting through the 'cookie_notice_options[refuse_code_head]' parameter. This flaw arises from inadequate input sanitization and output escaping practices, enabling authenticated attackers with administrative privileges to inject malicious web scripts. These scripts may execute whenever a user accesses the affected /wp-admin/admin.php?page=cookie-notice page. The vulnerability is specifically present in multi-site installations and those where unfiltered_html has been disabled, posing a significant risk to the integrity and security of affected websites.
Affected Version(s)
Cookie Notice & Compliance for GDPR / CCPA * <= 2.4.17.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved