Developers of the popular WordPress plugin have addressed a critical bug that could potentially impact 700K users. The vulnerability was reported to the development team by the security researcher Jerome Bruandet from NinTechNet. The plugin is developed by WebToffee that addressed the flaw with the release of version 1.8.3, less than a week after the disclosure of the issues. An attacker could exploit the flaw to inject JavaScript code that will be automatically loaded and executed every time a user (authenticated or not) visits the / cli -policy-preview/ page.”]
Source: https://securityaffairs.co/wordpress/97755/hacking/wordpress-cookie-consent-plugin-flaw.html

