CVE-2020-20633: Cookielawinfo Gdpr Cookie Consent

Medium severity, CVSS 5.4. EPSS: 0.9% chance of exploitation in the next 30 days.

ajax_policy_generator in admin/modules/cli-policy-generator/classes/class-policy-generator-ajax.php in GDPR Cookie Consent (cookie-law-info) 1.8.2 and below plugin for WordPress, allows authenticated stored XSS and privilege escalation.

Affected products

Published 2020-08-21. Last modified 2026-06-17.