Impact
An attacker can exploit the plugin’s insufficient sanitization of comment content to embed KSES‑allowed markup such as abbr title attributes and HTML comments. The global strtr substitution function then alters these inert substrings into executable elements like an img tag with an onerror handler that runs arbitrary JavaScript in the WordPress origin whenever a page containing the injected comment is loaded. The malicious script executes for every visitor, including logged‑in administrators, allowing credential theft, session hijacking, or defacement.
Affected Systems
All installations of the iubenda All‑in‑one Compliance for GDPR / CCPA Cookie Consent + more WordPress plugin that are version 3.13.4 or earlier. The vulnerability affects any WordPress site that has this plugin activated and allows comment submission.
Risk and Exploitability
The CVSS score of 7.2 indicates high risk, and although the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the attack is straightforward: an unauthenticated attacker merely submits a crafted comment, which then executes on any visitor's browser. This attack vector enables widespread impact across all users of the site and poses significant confidentiality, integrity, and availability threats.
OpenCVE Enrichment