CVE-2023-33333
The Complianz – GDPR/CCPA Cookie Consent plugin through version 6.4.4 (free) and 6.4.6.1 (premium) contains a cross-site request forgery vulnerability allowing stored cross-site scripting attacks. The ajax_script_add() and ajax_script_save() functions lack proper nonce verification on their AJAX handlers, enabling attackers to inject malicious scripts into a website if they can deceive an administrator into clicking a malicious link. An unauthenticated attacker can exploit this flaw to execute arbitrary code on the affected site.
Based on public CVE data (MITRE/NVD).