vendor:
UK Cookie Consent
by:
B0UG
5.4
CVSS
MEDIUM
Persistent Cross-Site Scripting
79
CWE
Product Name: UK Cookie Consent
Affected Version From: 2.3.9
Affected Version To: 2.3.9
Patch Exists: YES
Related CWE: CVE-2018-10310
CPE: a:catapultthemes:uk_cookie_consent
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: WordPress
2018
Exploit Title: UK Cookie Consent v2.3.9 – Persistent Cross-Site Scripting
A persistent cross-site scripting vulnerability has been identified in the web interface of the plugin that allows the execution of arbitrary HTML/script code to be executed in a victim's web browser.
Mitigation:
Update to the latest version available. Implement a web application such as Wordfence.