Complianz Premium [complianz-gdpr-premium] < 6.4.8
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Really Simple Plugins Complianz, Really Simple Plugins Complianz Premium allows Cross-Site Request Forgery.This issue affects Complianz: from n/a through 6.4.5; Complianz Premium: from n/a through 6.4.7.
- Affected:
- up to 6.4.8
- Fixed in:
- 6.4.8
- Disclosed:
- Nov 30, 2023
CVE-2023-34030 on NVD →
Complianz Premium [complianz-gdpr-premium] < 6.4.7
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Really Simple Plugins Complianz, Really Simple Plugins Complianz Premium allows Cross-Site Scripting (XSS).This issue affects Complianz: from n/a through 6.4.4; Complianz Premium: from n/a through 6.4.6.1.
- Affected:
- up to 6.4.7
- Fixed in:
- 6.4.7
- Disclosed:
- Nov 30, 2023
CVE-2023-33333 on NVD →
Complianz <= 6.4.4 (Premium <= 6.4.6.1) - Cross-Site Request Forgery to Stored Cross-Site Scripting
medium
The Complianz plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting in versions up to, and including, 6.4.4 (Free) and 6.4.6.1 (Premium). This is due to missing nonce validation on the ajax_script_add() and ajax_script_save() functions called via AJAX actions. This makes it pos...
- CVSS:
- 6.1
- Affected:
- up to 6.4.6.1
- Fixed in:
- 6.4.7
- Disclosed:
- Jun 21, 2023
CVE-2023-33333 on NVD →
Complianz <= 6.4.5 (Premium <= 6.4.7) - Cross-Site Request Forgery
medium
The Complianz plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting in versions up to, and including, 6.4.5 (Free) and 6.4.7 (Premium). This is due to missing nonce validation on several functions called via AJAX actions such as cmplz_delete_cookiebanner(), cmplz_duplicate_cook...
- CVSS:
- 4.3
- Affected:
- up to 6.4.7
- Fixed in:
- 6.4.8
- Disclosed:
- Jun 20, 2023
CVE-2023-34030 on NVD →
Complianz - GDPR/CCPA Cookie Consent <= 6.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Complianz - GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in versions up to, and including, 6.4.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with co...
- CVSS:
- 6.4
- Affected:
- up to 6.4.1
- Fixed in:
- 6.4.2
- Disclosed:
- Mar 6, 2023
CVE-2023-1069 on NVD →
Complianz Premium [complianz-gdpr-premium] < 6.3.6
unknown
[en] The Complianz WordPress plugin before 6.3.4, and Complianz Premium WordPress plugin before 6.3.6 allow a translators to inject arbitrary SQL through an unsanitized translation. SQL can be injected through an infected translation file, or by a user with a translator role through translation plugins such as Loco Tra...
- Affected:
- up to 6.3.6
- Fixed in:
- 6.3.6
- Disclosed:
- Nov 7, 2022
CVE-2022-3494 on NVD →
Complianz Free <= 6.3.3 & Premium <= 6.3.5 - SQL Injection via Translations
high
The Complianz plugin for WordPress is vulnerable to SQL Injection via unescaped translations in versions up to, and including, 6.3.3 (Free) and 6.3.5 (Premium) due to insufficient escaping on the user supplied translation (either from a translation file or a user with translator role through a translation plugin) and l...
- CVSS:
- 8.8
- Affected:
- up to 6.3.5
- Fixed in:
- 6.3.6
- Disclosed:
- Oct 17, 2022
CVE-2022-3494 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database