PT-2026-95333 · WordPress · Gdpr Ccpa Compliance & Cookie Consent Banner+1

·

CVE-2026-83561

·

Published

2026-09-18

·

Updated

2026-09-18

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Complianz GDPR/CCPA Cookie Consent Banner versions prior to 7.5.5
Description Insufficient input sanitization and output escaping allow unauthenticated attackers to perform Stored Cross-Site Scripting (XSS) via comment content. This occurs through the Elementor Cookie Blocker Regex, enabling the injection of arbitrary web scripts that execute when a user visits the affected page. Successful exploitation requires an administrator to approve the malicious comment, the installation of the Elementor plugin, and the configuration of Complianz with the Twitter or Facebook cookie/script blocker enabled.
Recommendations Update to a version newer than 7.5.4. As a temporary mitigation, disable the Twitter or Facebook cookie/script blocker in the Complianz configuration.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-83561

Affected Products

Gdpr Ccpa Compliance & Cookie Consent Banner
Elementor