CVE-2022-3811


EU Cookie Law <= 3.1.6 - Admin+ Stored XSS

The EU Cookie Law for GDPR/CCPA WordPress plugin through 3.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).



We have discovered 15,982 live websites that are affected by CVE-2022-3811.

Contact us to get more info




Affected Software

Product  EU Cookie Law for GDPR/CCPA
Category Wordpress Plugins
Vulnerable Versions
  • from 0 through 3.1.6
Total Vulnerable Versions72
Vulnerable Domains15,982 live websites (99.44% of EU Cookie Law for GDPR/CCPA install base)


Common Weakness Enumeration


CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2022-3811 and the relative popularity of websites


Details

  • Published - Jan 23, 2023

Credits

  • zhangyunpei (finder)
  • WPScan (coordinator)





Countries

United States861 websites



Germany4,394 websites
Italy3,001 websites
Spain1,160 websites
Poland1,053 websites
Hungary794 websites
GB731 websites
France704 websites
Netherlands699 websites
Austria463 websites

TLDs

.com3,364 websites
.de3,306 websites
.it2,053 websites
.pl815 websites
.nl586 websites
.org519 websites
.es465 websites
.co.uk412 websites
.at392 websites
.net365 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2022-3811 through included software libraries and plugins.



References


Websites affected by CVE-2022-3811

Top websites that are affected by CVE-2022-3811. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***********.com United States*,***
*********.***********.eu Germany**,***
********.**.**.uk GB**,***
***.*************.com United States**,***
*************.com United States**,***
***.************.com United States**,***
***.***********.com United States**,***
***.********************.***.uk GB**,***
***.************.com United States**,***
***.*****************.net Germany**,***
See full domain list