CVE-2021-4358: WP DSGVO Tools (GDPR) <= 3.1.23 - Unauthenticated Stored Cross-Site Scripting
The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in versions up to, and including, 3.1.23 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-4358?
CVE-2021-4358 is classified as a high severity vulnerability due to its potential to allow stored cross-site scripting attacks.
How do I fix CVE-2021-4358?
To fix CVE-2021-4358, update the WP DSGVO Tools (GDPR) plugin to version 3.1.24 or later.
Who is affected by CVE-2021-4358?
CVE-2021-4358 affects all versions of the WP DSGVO Tools (GDPR) plugin for WordPress up to and including version 3.1.23.
What types of attacks does CVE-2021-4358 allow?
CVE-2021-4358 allows unauthenticated attackers to execute arbitrary JavaScript via stored cross-site scripting.
Is CVE-2021-4358 actively exploited in the wild?
Yes, CVE-2021-4358 has been reported to be actively exploited by attackers.