First published: Mon Jan 23 2023(Updated: )
The EU Cookie Law for GDPR/CCPA WordPress plugin through 3.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
EU Cookie Law | <=3.1.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-3811 is considered a critical vulnerability as it allows high privilege users to perform Stored Cross-Site Scripting attacks.
To fix CVE-2022-3811, update the EU Cookie Law plugin to a version newer than 3.1.6 where the vulnerability has been addressed.
CVE-2022-3811 affects WordPress users leveraging the EU Cookie Law for GDPR/CCPA plugin versions up to 3.1.6.
CVE-2022-3811 enables high privilege users to conduct Stored Cross-Site Scripting attacks on websites.
While the best mitigation is updating the plugin, restricting access to high privilege accounts can reduce the impact of CVE-2022-3811.