Impact
The plugin contains insufficient input sanitization and output escaping in its admin settings, which lets any user with administrator permissions embed JavaScript that is later stored and served to all site visitors. This stored cross‑site scripting can be used to hijack user sessions, deface pages, or redirect traffic, thereby compromising the confidentiality and integrity of the site’s users.
Affected Systems
Moove Agency’s GDPR Cookie Compliance plugin for WordPress – any version up to and including 4.15.6. The flaw is present in multisite installations and in configurations where the unfiltered_html WordPress setting has been disabled.
Risk and Exploitability
The CVSS score is 4.4, indicating a moderate level of impact, while the EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog. Because the attack requires administrative credentials, the vector is authenticated, but the exploitation is still serious because the injected script runs in every browser that views the affected page. The limited exploitation probability reflects the need for privileged access, yet once executed it can affect all users who access the site.
OpenCVE Enrichment
EUVD