CVE-2023-23678: WordPress WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin <= 2.2.5 - CSV Injection vulnerability
Published Nov 7, 2023
·Updated
A vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent gdpr-cookie-consent.This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through <= 2.2.5.
Affected Software
1 affected component
WPEka Wp Cookie Consent Wordpress<=2.2.5
Remediation
Information
Update to 2.2.6 or a higher version.
Event History
Nov 7, 2023
CVE Published
via MITRE·03:48 PM
Data Sourced
via MITRE·03:48 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-23678?
The severity of CVE-2023-23678 is high with a severity value of 7.2.
2
What is the vulnerability ID for the WordPress WP Cookie Notice for GDPR CCPA & ePrivacy Consent Plugin?
The vulnerability ID for the WordPress WP Cookie Notice for GDPR CCPA & ePrivacy Consent Plugin is CVE-2023-23678.
3
What is the affected software for CVE-2023-23678?
The affected software for CVE-2023-23678 is WpekaClub WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) version up to and including 2.2.5.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-23678?
The Common Weakness Enumeration (CWE) ID for CVE-2023-23678 is CWE-1236.
5
How do I fix CVE-2023-23678?
To fix CVE-2023-23678, update the WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) plugin to version 2.2.6 or later.