WPHizmet

Eklenti güvenlik geçmişi

Real Cookie Banner güvenlik açıkları

ABD Ulusal Güvenlik Açığı Veritabanı’nda (NVD) Real Cookie Banner: GDPR & ePrivacy Cookie Consent eklentisi için 4 açık kaydı bulunuyor; en yenisi 3 Ekim 2026 tarihli. Bunların 1 tanesi kritik veya yüksek önemde, 1 tanesi oturum açmadan istismar edilebiliyor. Güncel sürüm 5.3.8.

Toplam kayıt
4
Kritik veya yüksek
1
Oturumsuz istismar
1
Son kayıt
3 Ekim 2026

Bilinen açık kayıtları

En yeniden eskiye. Her kaydın özgün metni NVD’de.

  • CVE-2026-92977Yüksek · 7,23 Ekim 2026

    depolanmış siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 5.3.5 ve öncesi · Oturum açmadan istismar edilebilir

    The Real Cookie Banner: GDPR & ePrivacy Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment in all versions up to, and including, 5.3.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Malicious script payloads placed in the title attribute of an anchor tag survive WordPress's comment kses filter at save time, as the payload is only promoted to executable HTML attributes when the plugin's page-wide regex strips the closing quote delimiter at render time; exploitability is therefore subject to the standard comment moderation workflow before the comment is publicly displayed.

    Türkçe kayıt ve ne yapmalı
  • CVE-2025-12136Orta · 6,824 Ekim 2025

    sunucu taraflı istek sahteciliği (SSRF)

    Etkilenen sürümler: 5.2.4 ve öncesi

    The Real Cookie Banner: GDPR & ePrivacy Cookie Consent plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.2.4. This is due to insufficient validation on the user-supplied URL in the '/scanner/scan-without-login' REST API endpoint. This makes it possible for authenticated attackers, with administrator-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services via the `url` parameter.

  • CVE-2025-1485Orta · 4,82 Haziran 2025

    depolanmış siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 5.1.6 öncesi

    The Real Cookie Banner: GDPR & ePrivacy Cookie Consent WordPress plugin before 5.1.6, real-cookie-banner-pro WordPress plugin before 5.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

  • CVE-2022-4507Orta · 5,416 Ocak 2023

    depolanmış siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 3.4.10 öncesi

    The Real Cookie Banner WordPress plugin before 3.4.10 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins.

Kaynak: NVD (kamu malı veri) ve WordPress.org eklenti dizini. Kayıtlar eklentinin WordPress.org adresi veya tam adıyla eşleştirilir. Veri 7 Ekim 2026 itibarıyla.