Product
high
advisory
Stored XSS Vulnerability in Complianz WordPress Plugin
2 TTPs 1 CVEThe Complianz GDPR/CCPA Cookie Consent Banner plugin is vulnerable to Stored Cross-Site Scripting (XSS) via the Elementor Cookie Blocker, allowing attackers to execute arbitrary JavaScript in the context of an administrator-approved comment.
Complianz GDPR/CCPA Cookie Consent Banner +1
wordpress
xss
web-application
2t
1c
high
advisory
WordPress Hide My WP Lite Plugin Vulnerable to Arbitrary File Read (CVE-2026-13347)
1 rule 2 TTPs 1 CVEThe Hide My WP Lite plugin for WordPress, versions up to and including 1.3, is vulnerable to Arbitrary File Read (CVE-2026-13347) due to inadequate validation of user-supplied input in query parameters `he_wrapper_js` and `he_wrapper_css` within the `elementor_assets_filter()` function, allowing unauthenticated attackers to read arbitrary files on the server like `wp-config.php` when the Elementor plugin and 'Hide Elementor' feature are enabled.
Hide My WP Lite <= 1.3 +1
wordpress
plugin
arbitrary-file-read
path-traversal
web-application
cve
1r
2t
1c