Impact
The vulnerability is a stored cross‑site scripting flaw that arises when an attacker posts a comment containing malicious script. Because the plugin does not sanitize or escape the comment content correctly, the payload is stored and rendered in page output. The attack succeeds only if an administrator approves the comment and the site has both the Elementor plugin installed and the Complianz cookie/script blocker (Twitter or Facebook) enabled. The flaw is a CWE‑79 – Improper Neutralization of Input in Web Pages.
Affected Systems
The issue affects the Complianz GDPR/CCPA Cookie Consent Banner WordPress plugin version 7.5.4 and earlier. Affected sites must have both the Elementor plugin installed and the Complianz plugin configured with either the Twitter or Facebook cookie/script blocker enabled. No other versions or plugins are listed as vulnerable.
Risk and Exploitability
The CVSS score is 7.2, which represents a high severity. The EPSS score is below 1 %, indicating that exploitation is considered unlikely at this time, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through unauthenticated comment posting, requiring the comment to be approved by an administrator before the script is visible to site visitors. Successful exploitation would result in the execution of arbitrary JavaScript within the context of site users.
OpenCVE Enrichment