vendor:
Responsive Cookie Consent
by:
B0UG
5.4
CVSS
MEDIUM
Authenticated Persistent Cross-Site Scripting
79
CWE
Product Name: Responsive Cookie Consent
Affected Version From: 1.5
Affected Version To: 1.7
Patch Exists: YES
Related CWE: CVE-2018-10309
CPE: 2.3:a:wordpress:responsive_cookie_consent
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: WordPress
2018
WordPress Responsive Cookie Consent 1.7 / 1.6 / 1.5 – Authenticated Persistent Cross-Site Scripting
A authenticated persistent cross-site scripting vulnerability has been found in the web interface of the plugin that allows the execution of arbitrary HTML/script code to be executed in the victim's browser when they visit the web site. An attacker can execute malicious code in a victim's browser to perform various activities such as stealing cookies, session tokens, credentials and personal data amongst others.
Mitigation:
Update to the latest version available. Implement a web application such as Wordfence.