GDPR Cookie Consent & Compliance Notice <= 1.8.2 - Authenticated Stored Cross-Site Scripting and Authorization Bypass
mediumajax_policy_generator in admin/modules/cli-policy-generator/classes/class-policy-generator-ajax.php in GDPR Cookie Consent (cookie-law-info) 1.8.2 and below plugin for WordPress, allows authenticated stored XSS and privilege escalation.
- CVSS:
- 6.4
- Affected:
- up to 1.8.2
- Fixed in:
- 1.8.3
- Disclosed:
- Feb 11, 2020