Show filters
88 Total Results
Displaying 61-70 of 88
Sort by:
Attacker Value
Unknown

CVE-2021-24653

Disclosure Date: October 25, 2021 (last updated February 23, 2025)
The Cookie Bar WordPress plugin before 1.8.9 doesn't properly sanitise the Cookie Bar Message setting, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
Attacker Value
Unknown

CVE-2021-24595

Disclosure Date: October 18, 2021 (last updated February 23, 2025)
The Wp Cookie Choice WordPress plugin through 1.1.0 is lacking any CSRF check when saving its options, and do not escape them when outputting them in attributes. As a result, an attacker could make a logged in admin change them to arbitrary values including XSS payloads via a CSRF attack.
Attacker Value
Unknown

CVE-2021-24569

Disclosure Date: September 27, 2021 (last updated February 23, 2025)
The Cookie Notice & Compliance for GDPR / CCPA WordPress plugin before 2.1.2 does not escape the value of its Button Text setting when outputting it in an attribute in the frontend, allowing high privilege users such as admin to perform Cross-Site Scripting even when the unfiltered_html capability is disallowed.
Attacker Value
Unknown

CVE-2021-23442

Disclosure Date: September 17, 2021 (last updated February 23, 2025)
This affects all versions of package @cookiex/deep. The global proto object can be polluted using the __proto__ object.
Attacker Value
Unknown

CVE-2021-24590

Disclosure Date: September 06, 2021 (last updated February 23, 2025)
The Cookie Notice & Consent Banner for GDPR & CCPA Compliance WordPress plugin before 1.7.2 does not properly sanitize inputs to prevent injection of arbitrary HTML within the plugin's design customization options.
Attacker Value
Unknown

CVE-2021-24405

Disclosure Date: July 06, 2021 (last updated February 22, 2025)
The Easy Cookies Policy WordPress plugin through 1.6.2 is lacking any capability and CSRF check when saving its settings, allowing any authenticated users (such as subscriber) to change them. If users can't register, this can be done through CSRF. Furthermore, the cookie banner setting is not sanitised or validated before being output in all pages of the frontend and the backend settings one, leading to a Stored Cross-Site Scripting issue.
Attacker Value
Unknown

CVE-2020-20633

Disclosure Date: August 21, 2020 (last updated February 22, 2025)
ajax_policy_generator in admin/modules/cli-policy-generator/classes/class-policy-generator-ajax.php in GDPR Cookie Consent (cookie-law-info) 1.8.2 and below plugin for WordPress, allows authenticated stored XSS and privilege escalation.
Attacker Value
Unknown

CVE-2020-12742

Disclosure Date: May 13, 2020 (last updated February 21, 2025)
The iubenda-cookie-law-solution plugin before 2.3.5 for WordPress does not restrict URL sanitization to http protocols.
Attacker Value
Unknown

CVE-2016-1000236

Disclosure Date: November 19, 2019 (last updated November 08, 2023)
Node-cookie-signature before 1.0.6 is affected by a timing attack due to the type of comparison used.
Attacker Value
Unknown

CVE-2019-16522

Disclosure Date: October 16, 2019 (last updated November 27, 2024)
The eu-cookie-law plugin through 3.0.6 for WordPress (aka EU Cookie Law (GDPR)) is susceptible to Stored XSS due to improper encoding of several configuration options in the admin area and the displayed cookie consent message. This affects Font Color, Background Color, and the Disable Cookie text. An attacker with high privileges can attack other users.