Impact
The vulnerability is a stored Cross‑Site Scripting flaw in the Termageddon: Cookie Consent & Privacy Compliance WordPress plugin. Improper neutralization of input allows an attacker to inject JavaScript that is persisted and served to all users, enabling session hijacking, credential theft, or the injection of malicious code into the site’s front‑end. The flaw is an input validation weakness identified as CWE‑79.
Affected Systems
The affected product is the Termageddon: Cookie Consent & Privacy Compliance plugin for WordPress. Versions up to and including 1.8.1 are impacted. WordPress sites that have this plugin installed and enabled are susceptible.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score is reported as less than 1 %, suggesting that exploitation is currently unlikely. The flaw is not listed in the CISA KEV catalog. The likely attack vector involves submitting malicious input through the plugin’s settings or cookie‑consent interface, which is then stored and served to all site visitors.
OpenCVE Enrichment
EUVD