CVE-2021-36887

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
20/12/2021
Last modified:
03/01/2022

Description

Cross-Site Request Forgery (CSRF) vulnerability leading to Cross-Site Scripting (XSS) discovered in tarteaucitron.js – Cookies legislation & GDPR WordPress plugin (versions

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:tarteaucitron.js_-_cookies_legislation_\&_gdpr_project:tarteaucitron.js_-_cookies_legislation_\&_gdpr:*:*:*:*:*:wordpress:*:* 1.5.4 (including)