Really-simple-plugins

Complianz

8 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.15%
  • Veröffentlicht 18.04.2024 11:15:37
  • Zuletzt bearbeitet 21.11.2024 09:13:05

Server-Side Request Forgery (SSRF) vulnerability in Really Simple Plugins Really Simple SSL.This issue affects Really Simple SSL: from n/a through 7.2.3.

  • EPSS 0.06%
  • Veröffentlicht 02.03.2024 07:15:46
  • Zuletzt bearbeitet 01.08.2025 02:04:53

The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.5.6. This is due to missing or incorrect nonce validation on the process_delete function in class-DNSMPD...

  • EPSS 0.1%
  • Veröffentlicht 04.01.2024 04:15:09
  • Zuletzt bearbeitet 21.11.2024 08:43:58

The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to and including 6.5.5 due to insufficient input sanitization and output escaping. This makes it possible...

  • EPSS 0.14%
  • Veröffentlicht 30.11.2023 14:15:09
  • Zuletzt bearbeitet 21.11.2024 08:06:26

Cross-Site Request Forgery (CSRF) vulnerability in Really Simple Plugins Complianz, Really Simple Plugins Complianz Premium allows Cross-Site Request Forgery.This issue affects Complianz: from n/a through 6.4.5; Complianz Premium: from n/a through 6....

  • EPSS 0.18%
  • Veröffentlicht 30.11.2023 14:15:08
  • Zuletzt bearbeitet 21.11.2024 08:05:26

Cross-Site Request Forgery (CSRF) vulnerability in Really Simple Plugins Complianz, Really Simple Plugins Complianz Premium allows Cross-Site Scripting (XSS).This issue affects Complianz: from n/a through 6.4.4; Complianz Premium: from n/a through 6....

Exploit
  • EPSS 0.19%
  • Veröffentlicht 27.03.2023 16:15:09
  • Zuletzt bearbeitet 18.02.2025 21:15:14

The Complianz WordPress plugin before 6.4.2, Complianz Premium WordPress plugin before 6.4.2 do not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users ...

Exploit
  • EPSS 0.92%
  • Veröffentlicht 07.11.2022 10:15:12
  • Zuletzt bearbeitet 01.05.2025 20:15:33

The Complianz WordPress plugin before 6.3.4, and Complianz Premium WordPress plugin before 6.3.6 allow a translators to inject arbitrary SQL through an unsanitized translation. SQL can be injected through an infected translation file, or by a user wi...

Exploit
  • EPSS 0.21%
  • Veröffentlicht 14.02.2022 12:15:16
  • Zuletzt bearbeitet 21.11.2024 06:38:06

The Complianz WordPress plugin before 6.0.0 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting