Zitec
38 Case Studies
A Zitec Case Study
The customer, WebToffee, provides a GDPR Cookies Consent plugin for WordPress, designed to help businesses comply with global privacy regulations. During a routine penetration test for another client, Zitec uncovered a critical blind XSS vulnerability (CVE-2024-8397) within this widely-used plugin, which posed a severe threat to the data security and administrative control of over 30,000 websites that relied on it.
Zitec collaborated with WebToffee to develop and implement a solution, which was released in the plugin's version 3.0.0. The fix introduced stricter input validation for HTTP headers and replaced the display of IP addresses with Consent IDs. This patch successfully eliminated the vulnerability, ensuring the plugin remained secure and GDPR-compliant for its vast user base, thereby safeguarding tens of thousands of businesses from potential data breaches and regulatory fines.