Description
Cross-Site Request Forgery (CSRF) vulnerability leading to Cross-Site Scripting (XSS) discovered in tarteaucitron.js – Cookies legislation & GDPR WordPress plugin (versions <= 1.5.4), vulnerable parameters "tarteaucitronEmail" and "tarteaucitronPass".
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update to 1.6 or higher version.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-23463 | Cross-Site Request Forgery (CSRF) vulnerability leading to Cross-Site Scripting (XSS) discovered in tarteaucitron.js – Cookies legislation & GDPR WordPress plugin (versions <= 1.5.4), vulnerable parameters "tarteaucitronEmail" and "tarteaucitronPass". |
References
History
Fri, 28 Mar 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2026-04-28T16:07:36.669Z
Reserved: 2021-07-19T00:00:00.000Z
Link: CVE-2021-36887
Updated: 2024-08-04T01:01:59.826Z
Status : Modified
Published: 2021-12-20T21:15:08.210
Modified: 2024-11-21T06:14:15.250
Link: CVE-2021-36887
No data.
OpenCVE Enrichment
No data.
EUVD