CVE Database /
CVE-2021-24569
CVE · Medium
CVE-2021-24569 — Cookie Compliance for WordPress – Cookie Consent, GDPR & CCPA [cookie-notice] < 2.1.4
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2021-24569
|
Cookie Compliance for WordPress – Cookie Consent, GDPR & CCPA [cookie-notice] < 2.1.4 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
4.8
|
< 2.1.4
|
2.1.4 |
2021-08-30 |
—
|
CVE-2021-24569
The Cookie Notice plugin for WordPress contains a stored cross-site scripting vulnerability in versions through 2.1.3 affecting the Button Text configuration option. The flaw arises from inadequate sanitization of user inputs and insufficient escaping of displayed content, permitting administrators and higher-privileged users to introduce malicious scripts that run when site visitors load affected pages. This vulnerability only impacts multisite WordPress installations or single-site setups where the unfiltered_html capability has been restricted.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings