Impact
The vulnerability arises from insufficient sanitization of user supplied attributes in the cookies_accepted shortcode of the Cookie Notice & Compliance for GDPR / CCPA plugin. This permits authenticated WordPress users with contributor-level or higher access to store arbitrary JavaScript that is rendered when any visitor views a page containing the shortcode. The stored payload can be used to hijack sessions, steal credentials, or deface the site, compromising both confidentiality and integrity of user data.
Affected Systems
All WordPress sites using the humanityco Cookie Notice & Compliance for GDPR / CCPA plugin up to and including version 2.5.8 are affected. The issue exists within the plugin’s cookies_accepted shortcode functionality, and any site that embeds this shortcode in posts, pages or widgets can be exploited. The vulnerability is only present in older releases; newer releases beyond 2.5.8 have been patched.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity, while the EPSS score of less than 1% suggests the likelihood of widespread exploitation remains low at present. Because the attack requires authenticated contributor privileges, a site’s internal user management configuration influences risk. Sites that grant many contributors write‑access are more vulnerable. The vulnerability is not listed in the CISA KEV catalog, so there are no confirmed widespread exploitation cases yet.
OpenCVE Enrichment