Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GDPR Info Cookie Notice & Consent Banner for GDPR & CCPA Compliance cookie-notice-and-consent-banner allows Stored XSS.This issue affects Cookie Notice & Consent Banner for GDPR & CCPA Compliance: from n/a through <= 1.7.11.
Published: 2025-09-03
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper neutralization of input during web page generation, resulting in a stored cross‑site scripting flaw. The flaw allows malicious JavaScript to be persisted in the plugin’s configuration and then executed whenever a site visitor loads the page. The impact can lead to session hijacking, defacement, or arbitrary script execution in the context of visiting users. Based on the description, it is inferred that an attacker could hijack users’ sessions or modify the site’s appearance.

Affected Systems

The affected product is the WordPress plugin named GDPR Info: Cookie Notice & Consent Banner for GDPR & CCPA Compliance. All releases up to and including version 1.7.11 are vulnerable, with no earlier safe version identified. Any WordPress site that has installed or enabled this plugin and is running version 1.7.11 or earlier may be compromised.

Risk and Exploitability

The CVSS score of 6.5 places the flaw in the medium severity range. The EPSS score of less than 1 % indicates a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation would likely be achieved by injecting malicious script payloads into stored configuration fields exposed through the plugin’s administrative interface; an attacker with permissions to edit these settings could affect all visitors to the site. The default privilege level required is unclear from the CVE data, but typical stored‑XSS vulnerabilities in WordPress plugins can be reached by users with administrative or editor access, and based on the description it is inferred that such access would also be sufficient here.

Generated by OpenCVE AI on April 30, 2026 at 07:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the GDPR Info: Cookie Notice & Consent Banner for GDPR & CCPA Compliance plugin to a version newer than 1.7.11.
  • Remove any content that may have already been injected by the attacker, such as scripts stored in the banner settings.
  • Enforce input sanitization on any user‑generated content, for example by enabling WordPress’ built‑in sanitization hooks or installing a security plugin that strips disallowed tags.

Generated by OpenCVE AI on April 30, 2026 at 07:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-26559 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GDPR Info Cookie Notice &amp; Consent Banner for GDPR &amp; CCPA Compliance allows Stored XSS. This issue affects Cookie Notice &amp; Consent Banner for GDPR &amp; CCPA Compliance: from n/a through 1.7.11.
History

Tue, 28 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GDPR Info Cookie Notice &amp; Consent Banner for GDPR &amp; CCPA Compliance cookie-notice-and-consent-banner allows Stored XSS.This issue affects Cookie Notice &amp; Consent Banner for GDPR &amp; CCPA Compliance: from n/a through <= 1.7.11. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GDPR Info Cookie Notice & Consent Banner for GDPR & CCPA Compliance cookie-notice-and-consent-banner allows Stored XSS.This issue affects Cookie Notice & Consent Banner for GDPR & CCPA Compliance: from n/a through <= 1.7.11.

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GDPR Info Cookie Notice &amp; Consent Banner for GDPR &amp; CCPA Compliance allows Stored XSS. This issue affects Cookie Notice &amp; Consent Banner for GDPR &amp; CCPA Compliance: from n/a through 1.7.11. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GDPR Info Cookie Notice &amp; Consent Banner for GDPR &amp; CCPA Compliance cookie-notice-and-consent-banner allows Stored XSS.This issue affects Cookie Notice &amp; Consent Banner for GDPR &amp; CCPA Compliance: from n/a through <= 1.7.11.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 03 Sep 2025 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Gdprinfo
Gdprinfo cookie Notice & Consent Banner For Gdpr & Ccpa Compliance
Wordpress
Wordpress wordpress
Vendors & Products Gdprinfo
Gdprinfo cookie Notice & Consent Banner For Gdpr & Ccpa Compliance
Wordpress
Wordpress wordpress

Wed, 03 Sep 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 03 Sep 2025 14:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GDPR Info Cookie Notice &amp; Consent Banner for GDPR &amp; CCPA Compliance allows Stored XSS. This issue affects Cookie Notice &amp; Consent Banner for GDPR &amp; CCPA Compliance: from n/a through 1.7.11.
Title WordPress Cookie Notice & Consent Banner for GDPR & CCPA Compliance Plugin <= 1.7.11 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Gdprinfo Cookie Notice & Consent Banner For Gdpr & Ccpa Compliance
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-12T00:39:30.732Z

Reserved: 2025-09-03T09:02:38.120Z

Link: CVE-2025-58607

cve-icon Vulnrichment

Updated: 2025-09-03T17:38:04.884Z

cve-icon NVD

Status : Deferred

Published: 2025-09-03T15:15:42.377

Modified: 2026-04-28T19:34:09.480

Link: CVE-2025-58607

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T07:30:31Z

Weaknesses