Vendor
high
advisory
Stored XSS in WPLP Cookie Consent Plugin for WordPress
2 TTPs 1 CVEAn unauthenticated Stored Cross-Site Scripting (XSS) vulnerability in the WPLP Cookie Consent plugin (<= 4.4.1) allows attackers to inject arbitrary web scripts via the 'wpl_user_preference' parameter by leveraging a publicly exposed AJAX nonce.
Cookie Banner for GDPR / CCPA – WPLP Cookie Consent
2t
1c
high
advisory
Stored XSS Vulnerability in Cookie Banner for GDPR / CCPA Plugin
2 TTPs 1 CVEThe WPLP Cookie Consent plugin for WordPress is vulnerable to stored cross-site scripting due to insufficient input validation in the regionArray parameter, allowing script injection by authenticated or unauthenticated attackers.
Cookie Banner for GDPR / CCPA – WPLP Cookie Consent
2t
1c