Vendor
Appsaloon
Products
1
CVEs
2
Across products
2
Status
Private
Products
1- 2 CVEs
Recent CVEs
2| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-36697 | Hig | 0.48 | 7.3 | 0.01 | Jun 7, 2023 | The WP GDPR plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in versions up to, and including, 2.1.1. This makes it possible for unauthenticated attackers to delete any comment and modify the plugin’s settings. | ||
| CVE-2020-20628 | Med | 0.40 | 6.1 | 0.01 | Aug 31, 2020 | controller/controller-comments.php in WP GDPR plugin through 2.1.1 has unauthenticated stored XSS. |
- risk 0.48cvss 7.3epss 0.01
The WP GDPR plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in versions up to, and including, 2.1.1. This makes it possible for unauthenticated attackers to delete any comment and modify the plugin’s settings.
- risk 0.40cvss 6.1epss 0.01
controller/controller-comments.php in WP GDPR plugin through 2.1.1 has unauthenticated stored XSS.