vendor:
WF Cookie Consent
by:
B0UG
6.1
CVSS
MEDIUM
Authenticated Persistent Cross-Site Scripting
79
CWE
Product Name: WF Cookie Consent
Affected Version From: 1.1.3
Affected Version To: 1.1.3
Patch Exists: NO
Related CWE: CVE-2018-10371
CPE: WordPress websites
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: WordPress
2018
WF Cookie Consent – Authenticated Persistent Cross-Site Scripting
A authenticated persistent cross-site scripting vulnerability has been identified in the web interface of the plugin that allows the execution of arbitrary HTML/script code to be executed in a victim's web browser.
Mitigation:
Implement a web application such as Wordfence or uninstall the plugin.