Gtbabel <= 6.6.8 - Unauthenticated Cookie Stealing
highThe Gtbabel plugin for WordPress is vulnerable to cookie stealing in all versions up to, and including, 6.6.8. This is due to the plugin transmitting cookie data via a URL. This makes it possible for unauthenticated attackers to steal admin cookies which may make privilege escalation possible, if they can successfully...
- CVSS:
- 7.5
- Affected:
- up to 6.6.8
- Fixed in:
- 6.6.9
- Disclosed:
- Feb 17, 2025