WordPress Plugin Vulnerabilities

Cookie Law Bar <= 1.2.1 - Authenticated Stored Cross-Site Scripting (XSS)

Description

The plugin does not properly sanitise its Bar Message setting, allowing high privilege users to set an XSS payload in it, which will be triggered in all frontend page of the blog.

Proof of Concept

Affects Plugins

No known fix

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Mesut Cetin
Verified
Yes

Timeline

Publicly Published
2021-05-25 (about 4 years ago)
Added
2021-05-25 (about 4 years ago)
Last Updated
2021-05-26 (about 4 years ago)

Other