CVE Database /
CVE-2022-3911
CVE · High
CVE-2022-3911 — iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more [iubenda-cookie-law-solution] < 3.3.3
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-3911
|
iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more [iubenda-cookie-law-solution] < 3.3.3 |
Cross-Site Request Forgery (CSRF) |
High
8.8
|
< 3.3.3
|
3.3.3 |
2022-12-12 |
—
|
CVE-2022-3911
The iubenda plugin for WordPress up to version 3.3.2 contains a privilege escalation vulnerability caused by insufficient verification checks in multiple functions including 'process_actions' and 'ajax_save_options'. This flaw allows users with subscriber-level access to execute AJAX actions restricted to higher-privileged users, such as modifying plugin settings and escalating their own account permissions.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings