GDPR/CCPA Cookie Consent Banner <= 3.2 - Missing Authorization via handle_consent_toggle()
medium
The GDPR/CCPA Cookie Consent Banner plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the handle_consent_toggle() function in versions up to, and including, 3.2. This makes it possible for unauthenticated attackers to toggle consent.
- CVSS:
- 5.3
- Affected:
- up to 3.2
- Fixed in:
- 3.2.1
- Disclosed:
- Jun 6, 2024
CVE-2024-35692 on NVD →
GDPR/CCPA Cookie Consent Banner < 3.2.1 - Missing Authorization via handle_consent_toggle()
medium
- Affected:
- up to 3.2.1
- Fixed in:
- 3.2.1
- Disclosed:
- Jun 6, 2024
CVE-2024-35692 on NVD →
UK Cookie Consent <= 2.3.9 - Authenticated Stored Cross-Site Scripting (XSS)
medium
- Affected:
- up to 2.3.10
- Fixed in:
- 2.3.10
- Disclosed:
- Apr 24, 2018
CVE-2018-10310 on NVD →
Catapult UK Cookie Consent <= 2.3.9 - Stored Cross-Site Scripting
medium
A persistent cross-site scripting vulnerability has been identified in the web interface of the Catapult UK Cookie Consent plugin before 2.3.10 for WordPress that allows the execution of arbitrary HTML/script code in the context of a victim's browser.
- CVSS:
- 6.4
- Affected:
- up to 2.3.9
- Fixed in:
- 2.3.10
- Disclosed:
- Apr 22, 2018
CVE-2018-10310 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database