VYPR

Wp Gdpr

by Appsaloon

CVEs (2)

  • CVE-2020-36697HigJun 7, 2023
    risk 0.48cvss 7.3epss 0.01

    The WP GDPR plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in versions up to, and including, 2.1.1. This makes it possible for unauthenticated attackers to delete any comment and modify the plugin’s settings.

  • CVE-2020-20628MedAug 31, 2020
    risk 0.40cvss 6.1epss 0.01

    controller/controller-comments.php in WP GDPR plugin through 2.1.1 has unauthenticated stored XSS.