CVE Database /
CVE-2020-20633
CVE · Medium
CVE-2020-20633 — CookieYes – Cookie Banner for Cookie Consent (Easy to setup GDPR/CCPA Compliant Cookie Notice) [cookie-law-info] < 1.8.3
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2020-20633
|
CookieYes – Cookie Banner for Cookie Consent (Easy to setup GDPR/CCPA Compliant Cookie Notice) [cookie-law-info] < 1.8.3 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
5.4
|
< 1.8.3
|
1.8.3 |
2020-02-11 |
—
|
CVE-2020-20633
The CookieYes plugin before version 1.8.3 contained an access control vulnerability in the cli_policy_generator AJAX function that allowed low-privileged authenticated users, including subscribers, to modify any post or page by changing its status from published to draft and thereby hiding it from the website's frontend. Additionally, attackers could inject malicious code into post or page content through this same function, creating stored cross-site scripting vulnerabilities that would execute in the browsers of site visitors.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings