Impact
This vulnerability allows stored cross‑site scripting in the GDPR Tools WordPress plugin. An attacker can inject malicious JavaScript into the website’s output, which will execute in the browsers of visitors who view the affected content. The impact includes theft of session cookies, unauthorized manipulation of the site’s user interface, and phishing or defacement of the site’s pages.
Affected Systems
WordPress sites running the GDPR Tools plugin by rolomak, version equal to or earlier than 1.0.2, which has not yet been updated to the patched release.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score of less than 1% suggests a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through the web interface of the plugin, where user‑generated content is stored and later rendered without proper sanitization.
OpenCVE Enrichment
EUVD