Security for everyone

CVE-2022-0220 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in WordPress GDPR plugin for WordPress affects v. before 1.9.27.


Short Info




Single Scan

Can be used by

Asset Owner

Estimated Time

10 sec

Scan only one

Domain, Ipv4

Parent Category

CVE-2022-0220 Scanner Detail

The WordPress GDPR plugin is a tool designed to assist website owners in complying with EU data protection regulations by providing features such as user data access and deletion. This plugin is widely used and installed on a large number of websites, indicating its importance in the current digital landscape.

However, a vulnerability has been recently detected in this product, identified as CVE-2022-0220. This vulnerability results from the check_privacy_settings AJAX action not including an "application/json" content-type in its JSON data response. Additionally, the HTML payload is not properly escaped, leaving it open to interpretation by a web browser. 

When exploited, this vulnerability could allow attackers to execute Javascript code on the victim's browser, potentially leading to the theft of sensitive information such as login credentials, payment information, and other personal data. This vulnerability is of particular concern for unauthenticated users, as they share the same nonce, rendering them more susceptible to attack.

