PT-2018-9817 · WordPress · Catapult Uk Cookie Consent Plugin

B0Ug

·

Published

2018-04-25

·

Updated

2018-06-13

·

CVE-2018-10310

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Catapult UK Cookie Consent plugin versions prior to 2.3.10
Description: A persistent cross-site scripting issue has been identified in the web interface of the Catapult UK Cookie Consent plugin for WordPress, allowing the execution of arbitrary HTML/script code in the context of a victim's browser.
Recommendations: For versions prior to 2.3.10, update to version 2.3.10 or later to resolve the issue.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-10310

Affected Products

Catapult Uk Cookie Consent Plugin