Impact
The WP DSGVO Tools (GDPR) plugin is vulnerable to stored cross‑site scripting via the "lw_content_block" shortcode. All plugin versions up to and including 3.1.36 do not properly sanitize or escape user supplied attributes, allowing an authenticated contributor or higher to inject arbitrary scripts that run whenever a page containing the shortcode is accessed. This flaw can compromise the confidentiality and integrity of the affected website by executing malicious code in the context of legitimate users.
Affected Systems
The vulnerability affects the WordPress plugin legalweb:WP DSGVO Tools (GDPR) for all releases up to version 3.1.36.
Risk and Exploitability
The CVSS score of 6.4 reflects a medium severity issue, while the EPSS score of less than 1% indicates a low likelihood of exploitation in the current marketplace, and the flaw is not listed in the CISA KEV catalog. Exploitation requires authenticated access at contributor level or higher, which is typically granted to regular content editors. Once the attacker injects script via the shortcode, the malicious code will execute in the browsers of all users who view the affected page, potentially leading to session hijacking, defacement, or data theft.
OpenCVE Enrichment