WordPress GDPR & CCPA <= 1.9.26 Reflected Cross-Site Scripting

2022-01-26 00:00
Ace Candelario

Strategic Overview

Status
Patched in 1.9.27
Affected PluginWordPress GDPR
Affected Version< 1.9.27
CVSS6.5Medium
CVECVE-2022-0220
View all WordPress GDPR vulnerabilities

Vulnerability Overview

The check_privacy_settings AJAX action of the WordPress GDPR WordPress plugin before 1.9.27, available to both unauthenticated and authenticated users, responds with JSON data without an "application/json" content-type. Since an HTML payload isn't properly escaped, it may be interpreted by a web browser led to this endpoint. Javascript code may be executed on a victim's browser. Due to v1.9.26 adding a CSRF check, the XSS is only exploitable against unauthenticated users (as they all share the same nonce)

Technical Analysis

REMEDIATION: Update to version 1.9.27, or a newer patched version --- IDENTIFIER: CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')) The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C