5.4
CVSSv3

CVE-2018-10310

Published: 25/04/2018 Updated: 13/06/2018
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 355
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

A persistent cross-site scripting vulnerability has been identified in the web interface of the Catapult UK Cookie Consent plugin prior to 2.3.10 for WordPress that allows the execution of arbitrary HTML/script code in the context of a victim's browser.

Vulnerable Product Search on Vulmon Subscribe to Product

catapultthemes cookie consent

Exploits

# Exploit Title: UK Cookie Consent v239 - Persistent Cross-Site Scripting # Date: 2018-04-22 # Exploit Author: B0UG # Vendor Homepage: catapultthemescom/ # Software Link: en-gbwordpressorg/plugins/uk-cookie-consent/#description # Version: Tested on version 239 (older versions may also be affected) # Tested on: WordPress # Cat ...
WordPress UK Cookie Consent plugin version 239 suffers from a persistent cross site scripting vulnerability ...