PT-2026-95333 · WordPress · Gdpr Ccpa Compliance & Cookie Consent Banner+1
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Complianz GDPR/CCPA Cookie Consent Banner versions prior to 7.5.5
Description
Insufficient input sanitization and output escaping allow unauthenticated attackers to perform Stored Cross-Site Scripting (XSS) via comment content. This occurs through the Elementor Cookie Blocker Regex, enabling the injection of arbitrary web scripts that execute when a user visits the affected page. Successful exploitation requires an administrator to approve the malicious comment, the installation of the Elementor plugin, and the configuration of Complianz with the Twitter or Facebook cookie/script blocker enabled.
Recommendations
Update to a version newer than 7.5.4.
As a temporary mitigation, disable the Twitter or Facebook cookie/script blocker in the Complianz configuration.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gdpr Ccpa Compliance & Cookie Consent Banner
Elementor