Beta

Report

Cookies and Content Security Policy <= 2.15 is vulnerable to Sensitive Data Exposure vulnerability

Unauthenticated
Published
2023-08-17

The Cookies and Content Security Policy plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.15 via the cacsp_texts function. This can allow unauthenticated attackers to extract sensitive data including the administrator email address.

CVSS

Score:5.3

Severity:Medium

Version: 2.15

There is a patch available in v2.16 and we strongly recommend you update to this version as soon as possible.