{"error":0,"message":null,"data":{"name":"CookieYes \u2013 Cookie Banner for Cookie Consent (Easy to setup GDPR\/CCPA Compliant Cookie Notice)","plugin":"cookie-law-info","link":"https:\/\/wordpress.org\/plugins\/cookie-law-info\/","latest":"1789022160","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"7f714d1a110595851d9deb3a4c8eee54c42c1efd1b3d1aed4181509be0afda01","name":"CookieYes \u2013 Cookie Banner for Cookie Consent (Easy to setup GDPR\/CCPA Compliant Cookie Notice) [cookie-law-info] < 1.8.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.8.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2020-20633","name":"CVE-2020-20633","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2020-20633","description":"[en] ajax_policy_generator in admin\/modules\/cli-policy-generator\/classes\/class-policy-generator-ajax.php in GDPR Cookie Consent (cookie-law-info) 1.8.2 and below plugin for WordPress, allows authenticated stored XSS and privilege escalation.","date":"2020-08-21"},{"id":"510b529d-c4a2-4605-8498-b53a2f8f1dd9","name":"GDPR Cookie Consent &lt; 1.8.3 - Improper Access Controls","link":"https:\/\/wpscan.com\/vulnerability\/510b529d-c4a2-4605-8498-b53a2f8f1dd9","description":"Improper Access Controls issue in the cli_policy_generator AJAX call which could allow an authenticated user with low privileges (such as a subscriber) to:\r\n\r\n- Change the status of any post\/page from published to draft, removing them from the frontend of the blog.\r\n\r\n- Put a payload in the content of one of them, leading to Stored Cross-Site Scripting (XSS) issues.","date":null},{"id":"9ef8353005d1066e1c03b6d04590ebc0d13e74cd","name":"GDPR Cookie Consent & Compliance Notice <= 1.8.2 - Authenticated Stored Cross-Site Scripting and Authorization Bypass","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/cookie-law-info\/gdpr-cookie-consent-compliance-notice-182-authenticated-stored-cross-site-scripting-and-authorization-bypass","description":"ajax_policy_generator in admin\/modules\/cli-policy-generator\/classes\/class-policy-generator-ajax.php in GDPR Cookie Consent (cookie-law-info) 1.8.2 and below plugin for WordPress, allows authenticated stored XSS and privilege escalation.","date":"2020-02-11"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"d309c62dd0de5a6d936b9c4ebe3a74ad6f5480483b3024bbabac8dc519e68849","name":"CookieYes \u2013 Cookie Banner for Cookie Consent (Easy to setup GDPR\/CCPA Compliant Cookie Notice) [cookie-law-info] < 1.8.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.8.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"2f904da41ca31e00a6ade900a76455d7939ccb59","name":"WordPress GDPR Cookie Consent plugin <= 1.8.2 - Improper Access Controls vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/cookie-law-info\/vulnerability\/wordpress-gdpr-cookie-consent-plugin-1-8-2-improper-access-controls-vulnerability","description":"Improper Access Controls vulnerability found by Jerome Bruandet in WordPress GDPR Cookie Consent plugin (versions <= 1.8.2).","date":"2020-02-12"}],"impact":[]}]},"updated":"1776153795"}