What the vulnerability does
01Description
Multiple Stored Authenticated Cross-Site Scripting (XSS) vulnerabilities were discovered in tarteaucitron.js – Cookies legislation & GDPR WordPress plugin (versions <= 1.6).
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:L/A:N
What the vulnerability does
Multiple Stored Authenticated Cross-Site Scripting (XSS) vulnerabilities were discovered in tarteaucitron.js – Cookies legislation & GDPR WordPress plugin (versions <= 1.6).
Explanation of Vulnerability in Simple Terms
The tarteaucitron.js WordPress plugin version 1.6 and earlier contains a cross-site scripting (XSS) vulnerability in how it handles user input. An authenticated administrator with high privileges can inject malicious scripts that affect other users' browsers when they interact with the plugin's interface. The vulnerability requires user interaction to trigger and has limited scope, but can compromise site integrity.
What an attacker can do
Inject malicious scripts that execute in other users' browsers when they interact with the plugin.
Potential impact on your site
An admin account holder could inject scripts affecting other site users, potentially stealing session tokens or modifying site content.
Conditions required to exploit
Attacker must be an authenticated administrator (high privileges) and the victim must click a link or visit a page containing the malicious payload.
Key dates
External resources
Related vulnerabilities