blog.nintechnet.com
https://blog.nintechnet.com/wordpress-wp-dsgvo-tools-gdpr-plugin-patched-vulnerability-actively-exploited CVE-2021-4358
HIGH
WP DSGVO Tools (GDPR) <= 3.1.23 - Unauthenticated Stored Cross-Site Scripting
Record summary
CVE-2021-4358 has a selected CVSS score of 7.2 (high).
Description
The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in versions up to, and including, 3.1.23 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jun 7, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 5, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
WP DSGVO Tools (GDPR)Browse legalweb / WP DSGVO Tools (GDPR)Default status: unaffected | CVE List | Before 3.1.24 | affected |
wp_dsgvo_toolsBrowse legalweb / wp_dsgvo_tools | VulnCheck | Version data not supplied | |
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-4358 wordpress.org
https://wordpress.org/support/topic/weiterleitung-redirects wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/6c18ab1b-02f1-4679-8cff-679d98dc9f4a?source=cve