Case Study: WebToffee GDPR Cookies Consent Plugin strengthens security and GDPR compliance with Zitec

A Zitec Case Study

Preview of the WebToffee GDPR Cookies Consent Plugin Case Study

WebToffee GDPR Cookies Consent Plugin secures 30,000+ websites with Zitec

The customer, WebToffee, provides a GDPR Cookies Consent plugin for WordPress, designed to help businesses comply with global privacy regulations. During a routine penetration test for another client, Zitec uncovered a critical blind XSS vulnerability (CVE-2024-8397) within this widely-used plugin, which posed a severe threat to the data security and administrative control of over 30,000 websites that relied on it.

Zitec collaborated with WebToffee to develop and implement a solution, which was released in the plugin's version 3.0.0. The fix introduced stricter input validation for HTTP headers and replaced the display of IP addresses with Consent IDs. This patch successfully eliminated the vulnerability, ensuring the plugin remained secure and GDPR-compliant for its vast user base, thereby safeguarding tens of thousands of businesses from potential data breaches and regulatory fines.


View this case study…

Zitec

38 Case Studies