What the vulnerability does
01Description
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Christoph Rado Cookie Notice & Consent plugin <= 1.6.0 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Christoph Rado Cookie Notice & Consent plugin <= 1.6.0 versions.
Explanation of Vulnerability in Simple Terms
Cookie Notice & Consent versions up to 1.6.0 contain a stored cross-site scripting (XSS) vulnerability. An authenticated administrator with high privileges can inject malicious scripts into the plugin settings. When other users view pages with the cookie notice, the injected script executes in their browsers, potentially stealing session data or performing actions on their behalf. The vulnerability requires both admin access and user interaction (page visit).
What an attacker can do
Inject malicious scripts that execute in visitors' browsers when they view the cookie notice.
Potential impact on your site
Malicious admins or compromised admin accounts can inject scripts affecting all site visitors, risking session hijacking or credential theft.
Conditions required to exploit
Attacker must have high-level admin privileges and a victim must visit a page displaying the cookie notice.
Key dates
External resources
Related vulnerabilities