Vulnerabilities
Vulnerable Software
The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not properly sanitize and escape the IP headers when logging them, allowing visitors to conduct Stored Cross-Site Scripting attacks. The payload gets triggered when an admin visits the 'Consent report' page and the malicious script is executed in the admin context.
CVSS Score
5.4
EPSS Score
0.003
Published
2025-05-15


Contact Us

Shodan ® - All rights reserved