Vulnerabilities > Appsaloon

DATE CVE VULNERABILITY TITLE RISK
2023-06-07 CVE-2020-36697 Missing Authorization vulnerability in Appsaloon WP Gdpr
The WP GDPR plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in versions up to, and including, 2.1.1.
network
low complexity
appsaloon CWE-862
6.5
2020-08-31 CVE-2020-20628 Cross-site Scripting vulnerability in Appsaloon Wp-Gdpr 2.1.1
controller/controller-comments.php in WP GDPR plugin through 2.1.1 has unauthenticated stored XSS.
network
low complexity
appsaloon CWE-79
6.1