PT-2026-72150 · WordPress · Cookie Banner For Gdpr / Ccpa

·

CVE-2026-13360

·

Published

2026-08-15

·

Updated

2026-08-20

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cookie Banner for GDPR / CCPA – WPLP Cookie Consent versions prior to 4.3.6
Description Stored Cross-Site Scripting (XSS) occurs due to insufficient input sanitization and output escaping. This allows unauthenticated attackers to inject arbitrary web scripts into pages that execute when accessed by users. Exploitation is possible if the site administrator has enabled the 'Support Google Consent Mode (GCM)' setting. Furthermore, the AJAX handler lacks nonce or capability checks, enabling any authenticated user, including those with Subscriber-level access, to overwrite the affected plugin setting via the regionArray parameter.
Recommendations Update the plugin to a version newer than 4.3.5. Disable the 'Support Google Consent Mode (GCM)' setting to prevent exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13360

Affected Products

Cookie Banner For Gdpr / Ccpa