PT-2018-9817 · WordPress · Catapult Uk Cookie Consent Plugin
B0Ug
·
Published
2018-04-25
·
Updated
2018-06-13
·
CVE-2018-10310
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Catapult UK Cookie Consent plugin versions prior to 2.3.10
Description:
A persistent cross-site scripting issue has been identified in the web interface of the Catapult UK Cookie Consent plugin for WordPress, allowing the execution of arbitrary HTML/script code in the context of a victim's browser.
Recommendations:
For versions prior to 2.3.10, update to version 2.3.10 or later to resolve the issue.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Catapult Uk Cookie Consent Plugin