controller/controller-comments.php in WP GDPR plugin through 2.1.1 has unauthenticated stored XSS.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-20628
Reference (s):
- https://blog.nintechnet.com/unauthenticated-stored-xss-and-content-spoofing-vulnerabilities-in-wordpress-wp-gdpr-plugin-unpatched/

