S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-0220 Scanner

CVE-2022-0220 scanner - Cross-Site Scripting (XSS) vulnerability in WordPress GDPR plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.1k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-0220
6.1
CVSS

The check_privacy_settings AJAX action of the WordPress GDPR WordPress plugin before 1.9.27, available to both unauthenticated and authenticated users, responds with JSON data without an "application/json" content-type. Since an HTML payload isn't properly escaped, it may be interpreted by a web browser led to this endpoint. Javascript code may be executed on a victim's browser. Due to v1.9.26 adding a CSRF check, the XSS is only exploitable against unauthenticated users (as they all share the same nonce)

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
WordPress GDPR
AFFECTED< 1.9.27SAFE ✓≥ 1.9.27
Updated Aug 22, 2026View on NVD →
Detail

The WordPress GDPR plugin is a tool designed to assist website owners in complying with EU data protection regulations by providing features such as user data access and deletion. This plugin is widely used and installed on a large number of websites, indicating its importance in the current digital landscape.

However, a vulnerability has been recently detected in this product, identified as CVE-2022-0220. This vulnerability results from the check_privacy_settings AJAX action not including an "application/json" content-type in its JSON data response. Additionally, the HTML payload is not properly escaped, leaving it open to interpretation by a web browser. 

When exploited, this vulnerability could allow attackers to execute Javascript code on the victim's browser, potentially leading to the theft of sensitive information such as login credentials, payment information, and other personal data. This vulnerability is of particular concern for unauthenticated users, as they share the same nonce, rendering them more susceptible to attack.

At s4e.io, we offer comprehensive pro features that allow businesses and individuals to easily and quickly identify vulnerabilities in their digital assets. Our platform offers real-time alerts, vulnerability scanning, and expert insights to ensure that website owners and administrators can stay up-to-date on the latest threats and protect their customers' data. Don't wait until it's too late - sign up for pro features today and safeguard your digital assets from potential threats.

 

REFERENCES

Solution Advice

To protect against this vulnerability, the following precautions can be taken:

  • Update the WordPress GDPR plugin to the latest version (v 1.9.27) to ensure the fix for this vulnerability is applied 
  • Implement HTTP response headers to enforce strict content-type, content-security-policy, and X-XSS-Protection 
  • Ensure that proper input sanitization is employed, including character encoding and content type validation, in any custom code or plugins
  • Utilize a web application firewall to block potential attacks and prevent data breaches
  • Train website users and administrators on safe browsing habits and the importance of regularly updating software 

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.