CVE-2020-36718 Information
Jun 08, 2023
cve
Description
The GDPR CCPA Compliance Support plugin for WordPress is vulnerable to PHP Object Injection in versions up to and including 2.3 via deserialization of untrusted input jt_gdpr_allow_permissions\ value. This allows unauthenticated attackers to inject a PHP Object.
Reference
https://blog.nintechnet.com/gdpr-ccpa-compliance-support-plugin-fixed-insecure-deserialization-vulnerability/ https://wpscan.com/vulnerability/92f1d6fb-c665-419e-a13b-688b1df6c395 https://plugins.trac.wordpress.org/changeset/2408938 https://wordpress.org/plugins/ninja-gdpr-compliance/#developers https://www.wordfence.com/threat-intel/vulnerabilities/id/a2871261-3231-4a52-9a38-bb3caf461e7d?source=cve https://plugins.trac.wordpress.org/changeset/2411356/ninja-gdpr-compliance
Share on: