cleantalk
Vulnerabilities and Security Researches

CookieYes – Cookie Banner for Cookie Consent (Easy to setup GDPR/CCPA Compliant Cookie Notice), CVE-2020-20633

CVE, Research URL

CVE-2020-20633

Published on
Aug 21, 2020
Research Description
ajax_policy_generator in admin/modules/cli-policy-generator/classes/class-policy-generator-ajax.php in GDPR Cookie Consent (cookie-law-info) 1.8.2 and below plugin for WordPress, allows authenticated stored XSS and privilege escalation.
Affected versions
Min -, max 1.8.3.
Status
vulnerable