Skip to content

Known CVE

WordPress GDPR & CCPA <1.9.27 - Cross-Site Scripting

WordPress GDPR & CCPA plugin before 1.9.27 contains a cross-site scripting vulnerability. The check_privacy_settings AJAX action, available to both unauthenticated and authenticated users, responds with JSON data without an "application/json" content-type, and JavaScript code may be executed on a victim's browser.

CVE-2022-0220

Medium2022CVSS 6.1CWE-116

cve2022 · wpscan · wordpress · wp-plugin · wp · xss · unauth · welaunch

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website