CVE-2024-3201: WP DSGVO Tools (GDPR) <= 3.1.32 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pplink' shortcode in all versions up to, and including, 3.1.32 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3201?
CVE-2024-3201 has a high severity rating due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-3201?
To fix CVE-2024-3201, update the WP DSGVO Tools (GDPR) plugin to version 3.1.33 or later.
What versions of WP DSGVO Tools (GDPR) are affected by CVE-2024-3201?
CVE-2024-3201 affects all versions of WP DSGVO Tools (GDPR) up to and including 3.1.32.
What type of vulnerability is CVE-2024-3201?
CVE-2024-3201 is categorized as a Stored Cross-Site Scripting (XSS) vulnerability.
Can CVE-2024-3201 be exploited remotely?
Yes, CVE-2024-3201 can be exploited remotely if the affected plugin is installed and active.