ZeroHour

Vulnerabilities

2 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-36697
The WP GDPR plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in versions up to, and including, 2.1.1.

The WP GDPR plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in versions up to, and including, 2.1.1. This makes it possible for unauthenticated attackers to delete any comment and modify the plugin’s settings.

NVD description · AI analysis pending
6.5<1% PoC
  • appsaloon wp gdpr
CVE-2020-20628
controller/controller-comments.php in WP GDPR plugin through 2.1.1 has unauthenticated stored XSS.

controller/controller-comments.php in WP GDPR plugin through 2.1.1 has unauthenticated stored XSS.

NVD description · AI analysis pending
6.1<1% PoC
  • appsaloon wp-gdpr