CVE-2020-20633 – GDPR Cookie Consent & Compliance Notice <= 1.8.2 - Authenticated Stored Cross-Site Scripting and Authorization Bypass
https://notcve.org/view.php?id=CVE-2020-20633
ajax_policy_generator in admin/modules/cli-policy-generator/classes/class-policy-generator-ajax.php in GDPR Cookie Consent (cookie-law-info) 1.8.2 and below plugin for WordPress, allows authenticated stored XSS and privilege escalation. La función ajax_policy_generator en el archivo admin/modules/cli-policy-generator/classes/class-policy-generator-ajax.php en el plugin GDPR Cookie Consent (cookie-law-info) versiones 1.8.2 y por debajo para WordPress, permite un ataque de tipo XSS almacenado autenticado y una escalada de privilegios . • https://blog.nintechnet.com/wordpress-gdpr-cookie-consent-plugin-fixed-vulnerability • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •