Impact
The iubenda WordPress plugin contains a stored cross‑site scripting flaw caused by insufficient input sanitization and output escaping when comment content is processed by the AdSense regex rewrite within the secondary parser engine. An unauthenticated attacker can inject arbitrary JavaScript into a comment that is stored and later executed in any visitor’s browser, enabling session hijacking, defacement, or other malicious actions. The vulnerability is limited to installations that have the secondary parser engine active (parser_engine=default) and does not affect the newer DOM‑based parser.
Affected Systems
All installations of the iubenda | All‑in‑one Compliance for GDPR / CCPA Cookie Consent + more plugin for WordPress with versions up to and including 3.13.4, when the secondary parser engine is enabled. Sites using the newer DOM‑based parser engine are not affected.
Risk and Exploitability
The CVSS base score of 7.2 classifies this issue as high severity. The EPSS score is not available, making precise exploitation likelihood hard to gauge; however, because the flaw can be triggered via the public comment interface without any authentication, the attack surface is large. This vulnerability is not listed in the CISA KEV catalog. An attacker only needs to post a malicious comment, making the vector broadly exploitable. Given the high score and ease of exploitation, the risk to sites with the vulnerable plugin remains significant.
OpenCVE Enrichment