WordPress GDPR & CCPA plugin before 1.9.27 contains a cross-site scripting vulnerability. The check_privacy_settings AJAX action, available to both unauthenticated and authenticated users, responds with JSON data without an "application/json" content-type, and JavaScript code may be executed on a victim's browser.
id: CVE-2022-0220
info:
name: WordPress GDPR & CCPA <1.9.27 - Cross-Site Scripting
author: daf
...