CVE-2021-36887

All FrameworksWordPressCWE-352CVE-2021-36887

CVE-2021-36887

State: PUBLISHED · Published: 2021-12-20 · Updated: 2025-03-28 · Assigner: Patchstack
Description
Cross-Site Request Forgery (CSRF) vulnerability leading to Cross-Site Scripting (XSS) discovered in tarteaucitron.js – Cookies legislation & GDPR WordPress plugin (versions <= 1.5.4), vulnerable parameters "tarteaucitronEmail" and "tarteaucitronPass".
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2021/36xxx/CVE-2021-36887.json