Impact
The Easy EU Cookie law plugin contains an improper input neutralization flaw that allows stored Cross‑Site Scripting. A malicious script can be injected and persisted on the site, executing in the browsers of any visitor who loads the affected page. This could enable an attacker to steal session cookies, alter page content, or run arbitrary client‑side code. The weakness is classified as CWE‑79.
Affected Systems
The vulnerability affects the viher3 Easy EU Cookie law WordPress plugin for all versions from the earliest release up through 1.3.3.1. No specific patch version is listed in the description, but the issue applies to every installation of the plugin at or below this version.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity level, while the EPSS score of < 1% suggests a currently low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the nature of stored XSS in WordPress plugins, it is inferred that an attacker would need access to the plugin’s administration interface or a means to submit content that is saved to the database. Once the injected script is stored, any user who views the compromised page will be affected.
OpenCVE Enrichment
EUVD