CVE · High

CVE-2022-3494 — Complianz GDPR/CCPA Cookie Consent Banner [complianz-gdpr] < 6.3.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-3494 Complianz GDPR/CCPA Cookie Consent Banner [complianz-gdpr] < 6.3.4 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 8.8 < 6.3.4 6.3.4 2022-10-17

CVE-2022-3494

The Complianz plugin for WordPress versions 6.3.3 and earlier (free version) and 6.3.5 and earlier (premium version) contains a SQL injection vulnerability stemming from inadequately escaped translations and unprepared SQL queries. An attacker with translator role permissions or through a malicious translation file could inject arbitrary SQL commands to extract sensitive database information. The vulnerability arises from the plugin's failure to properly sanitize translation inputs before incorporating them into database queries.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.