Description
The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not properly sanitize and escape the IP headers when logging them, allowing visitors to conduct Stored Cross-Site Scripting attacks. The payload gets triggered when an admin visits the 'Consent report' page and the malicious script is executed in the admin context.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-15258 | The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not properly sanitize and escape the IP headers when logging them, allowing visitors to conduct Stored Cross-Site Scripting attacks. The payload gets triggered when an admin visits the 'Consent report' page and the malicious script is executed in the admin context. |
References
History
Thu, 12 Jun 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Webtoffee
Webtoffee gdpr Cookie Consent |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:webtoffee:gdpr_cookie_consent:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Webtoffee
Webtoffee gdpr Cookie Consent |
Sat, 17 May 2025 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 15 May 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not properly sanitize and escape the IP headers when logging them, allowing visitors to conduct Stored Cross-Site Scripting attacks. The payload gets triggered when an admin visits the 'Consent report' page and the malicious script is executed in the admin context. | |
| Title | GDPR Cookie Consent <= 2.6.0 - Unauthenticated Stored XSS | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-05-17T03:18:29.042Z
Reserved: 2024-09-03T17:37:12.054Z
Link: CVE-2024-8397
Updated: 2025-05-17T03:18:23.629Z
Status : Analyzed
Published: 2025-05-15T20:15:58.500
Modified: 2025-06-12T15:36:39.860
Link: CVE-2024-8397
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD