Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total2
Critical0
High0
Medium2
Reset
Showing 1-2 of 2 records
Threat Entry Updated 2025-06-12

CVE-2024-8286 - Webtoffee Gdpr Cookie Consent Plugin

The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting visit logs via CSRF attacks

PLUGIN Webtoffee Gdpr Cookie Consent

CVE-2024-8286

MEDIUM CVSS 6.5 2025-05-15
Threat Entry Updated 2025-06-12

CVE-2024-8397 - Webtoffee Gdpr Cookie Consent Plugin

The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not properly sanitize and escape the IP headers when logging them, allowing visitors to conduct Stored Cross-Site Scripting attacks. The payload gets triggered when an admin visits the 'Consent report' page and the malicious script is executed in the admin context.

PLUGIN Webtoffee Gdpr Cookie Consent

CVE-2024-8397

MEDIUM CVSS 5.4 2025-05-15
Scroll to top