sales@hackhalt.com

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3
Critical0
High0
Medium3
Reset
Showing 1-3 of 3 records
Threat Entry Updated 2026-08-26

Cookie Consent - Broken Access Control (CVE-2026-18046)

The Cookie Consent WordPress plugin before 0.0.10 does not correctly enforce its intended administrator-only capability check on the REST route that stores its geolocation service license key, so the route falls back to an authentication-only gate, allowing any authenticated user such as a subscriber to overwrite the stored key and disrupt the Cookie Consent WordPress plugin before 0.0.10's geolocation-based consent banner targeting.

PLUGIN Cookie Consent

CVE-2026-18046

MEDIUM CVSS 4.3 2026-08-12
Threat Entry Updated 2026-08-26

Cookie Consent - Broken Access Control (CVE-2026-15388)

The Cookie Consent WordPress plugin before 0.0.10 does not correctly enforce its intended administrator-only capability check on its consent-settings REST routes, so they fall back to an authentication-only gate, allowing any authenticated user such as a subscriber to update the Cookie Consent WordPress plugin before 0.0.10's consent settings and, on sites connected to the vendor's paid plan, read stored visitor consent logs.

PLUGIN Cookie Consent

CVE-2026-15388

MEDIUM CVSS 4.3 2026-08-12
Threat Entry Updated 2026-06-17

Cookie Consent - Cross-Site Scripting (XSS) (CVE-2018-10310)

A persistent cross-site scripting vulnerability has been identified in the web interface of the Catapult UK Cookie Consent plugin before 2.3.10 for WordPress that allows the execution of arbitrary HTML/script code in the context of a victim's browser.

PLUGIN Cookie Consent

CVE-2018-10310

MEDIUM CVSS 5.4 2018-04-25