plugin

Uk Cookie Consent Vulnerabilities

4 known security issues reported for the Uk Cookie Consent WordPress plugin. Most recent disclosed Jun 6, 2024.

4 medium

Running Uk Cookie Consent on your site? Check whether your installed version is affected.

Scan your site free

GDPR/CCPA Cookie Consent Banner <= 3.2 - Missing Authorization via handle_consent_toggle()

medium

The GDPR/CCPA Cookie Consent Banner plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the handle_consent_toggle() function in versions up to, and including, 3.2. This makes it possible for unauthenticated attackers to toggle consent.

CVSS:
5.3
Affected:
up to 3.2
Fixed in:
3.2.1
Disclosed:
Jun 6, 2024

CVE-2024-35692 on NVD →

GDPR/CCPA Cookie Consent Banner < 3.2.1 - Missing Authorization via handle_consent_toggle()

medium
Affected:
up to 3.2.1
Fixed in:
3.2.1
Disclosed:
Jun 6, 2024

CVE-2024-35692 on NVD →

UK Cookie Consent <= 2.3.9 - Authenticated Stored Cross-Site Scripting (XSS)

medium
Affected:
up to 2.3.10
Fixed in:
2.3.10
Disclosed:
Apr 24, 2018

CVE-2018-10310 on NVD →

Catapult UK Cookie Consent <= 2.3.9 - Stored Cross-Site Scripting

medium

A persistent cross-site scripting vulnerability has been identified in the web interface of the Catapult UK Cookie Consent plugin before 2.3.10 for WordPress that allows the execution of arbitrary HTML/script code in the context of a victim's browser.

CVSS:
6.4
Affected:
up to 2.3.9
Fixed in:
2.3.10
Disclosed:
Apr 22, 2018

CVE-2018-10310 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database