cleantalk
Vulnerabilities and Security Researches

GDPR CCPA Compliance Support, CVE-2020-36718

CVE, Research URL

CVE-2020-36718

Published on
Jun 07, 2023
Research Description
The GDPR CCPA Compliance Support plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.3 via deserialization of untrusted input "njt_gdpr_allow_permissions" value. This allows unauthenticated attackers to inject a PHP Object.
Affected versions
Min -, max 2.4.
Status
vulnerable