CVE-2020-20633: Cookielawinfo Gdpr Cookie Consent
Medium severity, CVSS 5.4. EPSS: 0.9% chance of exploitation in the next 30 days.
ajax_policy_generator in admin/modules/cli-policy-generator/classes/class-policy-generator-ajax.php in GDPR Cookie Consent (cookie-law-info) 1.8.2 and below plugin for WordPress, allows authenticated stored XSS and privilege escalation.
Affected products
- Cookielawinfo Gdpr Cookie Consent: up to and including 1.8.2
Published 2020-08-21. Last modified 2026-06-17.