EU Cookie Law <= 3.1.2 - Authenticated Stored Cross-Site Scripting

2019-10-16 00:00
Tobias Fink

Strategic Overview

Status
Patched in 3.1.3
Affected Version< 3.1.3
CVSS5.5Medium
CVECVE-2019-16522
View all EU Cookie Law for GDPR/CCPA vulnerabilities

Vulnerability Overview

The eu-cookie-law plugin through 3.0.6 for WordPress (aka EU Cookie Law (GDPR)) is susceptible to Stored XSS due to improper encoding of several configuration options in the admin area and the displayed cookie consent message. This affects Font Color, Background Color, and the Disable Cookie text. An attacker with high privileges can attack other users.

Technical Analysis

REMEDIATION: Update to version 3.1.3, or a newer patched version --- IDENTIFIER: CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')) The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C