PT-2026-72150 · WordPress · Cookie Banner For Gdpr / Ccpa
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Cookie Banner for GDPR / CCPA – WPLP Cookie Consent versions prior to 4.3.6
Description
Stored Cross-Site Scripting (XSS) occurs due to insufficient input sanitization and output escaping. This allows unauthenticated attackers to inject arbitrary web scripts into pages that execute when accessed by users. Exploitation is possible if the site administrator has enabled the 'Support Google Consent Mode (GCM)' setting. Furthermore, the AJAX handler lacks nonce or capability checks, enabling any authenticated user, including those with Subscriber-level access, to overwrite the affected plugin setting via the
regionArray parameter.Recommendations
Update the plugin to a version newer than 4.3.5.
Disable the 'Support Google Consent Mode (GCM)' setting to prevent exploitation.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cookie Banner For Gdpr / Ccpa