CVE · High

CVE-2023-33333 — Complianz GDPR/CCPA Cookie Consent Banner [complianz-gdpr] < 6.4.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-33333 Complianz GDPR/CCPA Cookie Consent Banner [complianz-gdpr] < 6.4.5 Cross-Site Request Forgery (CSRF) High 7.1 < 6.4.5 6.4.5 2023-05-12

CVE-2023-33333

The Complianz – GDPR/CCPA Cookie Consent plugin through version 6.4.4 (free) and 6.4.6.1 (premium) contains a cross-site request forgery vulnerability allowing stored cross-site scripting attacks. The ajax_script_add() and ajax_script_save() functions lack proper nonce verification on their AJAX handlers, enabling attackers to inject malicious scripts into a website if they can deceive an administrator into clicking a malicious link. An unauthenticated attacker can exploit this flaw to execute arbitrary code on the affected site.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.