CVE-2024-8397: GDPR Cookie Consent <= 2.6.0 - Unauthenticated Stored XSS
The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not properly sanitize and escape the IP headers when logging them, allowing visitors to conduct Stored Cross-Site Scripting attacks. The payload gets triggered when an admin visits the 'Consent report' page and the malicious script is executed in the admin context.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8397?
CVE-2024-8397 has been classified as a high severity vulnerability due to its potential for conducting Stored Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2024-8397?
To fix CVE-2024-8397, update the WebToffee GDPR Cookie Consent plugin to version 2.6.1 or later.
Which versions are affected by CVE-2024-8397?
CVE-2024-8397 affects all versions of the WebToffee GDPR Cookie Consent plugin prior to version 2.6.1.
What type of attacks can CVE-2024-8397 allow?
CVE-2024-8397 allows visitors to perform Stored Cross-Site Scripting attacks by exploiting improper sanitization of IP headers.
When does the payload for CVE-2024-8397 get triggered?
The payload for CVE-2024-8397 gets triggered when an admin accesses the 'Consent report' page.