The Cookie Information | Free GDPR Consent Solution WordPress plugin before 2.0.8 does not escape user data before outputting it back in attributes in the admin dashboard, leading to a Reflected Cross-Site Scripting issue
References
Link Resource
https://plugins.trac.wordpress.org/changeset/2681371 Patch Release Notes Third Party Advisory
https://wpscan.com/vulnerability/2c735365-69c0-4652-b48e-c4a192dfe0d1 Exploit Patch Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: WPScan

Published: 2022-03-14T14:41:17

Updated: 2022-03-14T14:41:17

Reserved: 2022-01-07T00:00:00


Link: CVE-2022-0147

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-03-14T15:15:09.417

Modified: 2022-03-21T05:17:57.793


Link: CVE-2022-0147

JSON object: View

cve-icon Redhat Information

No data.

CWE