4.8
CVSSv3

CVE-2021-24569

Published: 27/09/2021 Updated: 04/10/2021
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 4.8 | Impact Score: 2.7 | Exploitability Score: 1.7
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

The Cookie Notice & Compliance for GDPR / CCPA WordPress plugin prior to 2.1.2 does not escape the value of its Button Text setting when outputting it in an attribute in the frontend, allowing high privilege users such as admin to perform Cross-Site Scripting even when the unfiltered_html capability is disallowed.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

hu-manity cookie notice \\& compliance for gdpr \\/ ccpa