Impact
The vulnerability originates from improper neutralization of input during web page generation in the WP Cookie Consent plugin, which allows attackers to inject malicious scripts that are persisted in the web application. This stored XSS can execute arbitrary code in the browser of any user who views pages that display the injected content, potentially leading to theft of session data, defacement, or redirection to malicious sites. The weakness aligns with CWE‑79, representing a classic reflected or stored script injection flaw.
Affected Systems
The flaw affects WordPress users who have installed the WP Cookie Consent plugin by msmitley, any version equal to or older than version 1.0. Sites relying on this plugin for cookie consent banners are at risk if they have not upgraded beyond the affected release.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity, and the EPSS score of less than 1% shows a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed widespread exploitation. Based on the description, it is inferred that attackers would need to deliver malicious input through the plugin’s interface or data store, perhaps by exploiting administrative access or a user‑facing form that the plugin handles.
OpenCVE Enrichment
EUVD