Stored Cross-Site Scripting Vulnerability in WordPress GDPR Plugin Could Trigger Arbitrary Code Execution
CVE-2024-10388
What is CVE-2024-10388?
The WordPress GDPR plugin is susceptible to stored cross-site scripting due to inadequate input sanitization and output escaping for the 'gdpr_firstname' and 'gdpr_lastname' parameters. This vulnerability allows unauthenticated attackers to inject malicious web scripts into pages. When users access these compromised pages, the injected scripts can execute, potentially leading to unauthorized actions or data exposure. This issue affects all versions of the WordPress GDPR plugin up to and including 2.0.2, highlighting the critical need for users to apply necessary updates and maintain secure coding practices.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WordPress GDPR * <= 2.0.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved