VYPR

Cookie Law Bar

by WordPress

Source repositories

CVEs (2)

  • CVE-2021-47957MedMay 16, 2026
    risk 0.42cvss 6.4epss 0.00

    Cookie Law Bar 1.2.1 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting unsanitized input to the Bar Message field. Attackers can inject script payloads through the plugin settings page that execute…

  • CVE-2021-24653MedOct 25, 2021
    risk 0.31cvss 4.8epss 0.01

    The Cookie Bar WordPress plugin before 1.8.9 doesn't properly sanitise the Cookie Bar Message setting, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed