Impact
The vulnerability is a stored Cross‑Site Scripting flaw in the Cookie Law Bar plugin. The Bar Message field accepts unsanitized input, allowing an attacker who can access the plugin settings to inject scripts. When a malicious script is stored, it executes in the browsers of all WordPress users who view the site, enabling cookie theft, session hijacking, and sensitive data exfiltration.
Affected Systems
The flaw affects the Cookielawinfo Cookie Law Bar WordPress plugin, version 1.2.1, used on any WordPress site that installs this plugin. No other vendors or product versions are listed as impacted.
Risk and Exploitability
The CVSS base score is 5.1, giving the vulnerability a Medium severity rating. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploitation activity. Attackers require authenticated access to the WordPress admin area to inject scripts via the plugin’s settings page, limiting the attack surface to users with sufficient privileges.
OpenCVE Enrichment