Description
The Complianz GDPR/CCPA Cookie Consent Banner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via Elementor Cookie Blocker Regex in all versions up to, and including, 7.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires an administrator to approve the attacker's comment, and the site must have both the Elementor plugin installed and Complianz configured with the Twitter or Facebook cookie/script blocker enabled.
Published: 2026-09-18
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a stored cross‑site scripting flaw that arises when an attacker posts a comment containing malicious script. Because the plugin does not sanitize or escape the comment content correctly, the payload is stored and rendered in page output. The attack succeeds only if an administrator approves the comment and the site has both the Elementor plugin installed and the Complianz cookie/script blocker (Twitter or Facebook) enabled. The flaw is a CWE‑79 – Improper Neutralization of Input in Web Pages.

Affected Systems

The issue affects the Complianz GDPR/CCPA Cookie Consent Banner WordPress plugin version 7.5.4 and earlier. Affected sites must have both the Elementor plugin installed and the Complianz plugin configured with either the Twitter or Facebook cookie/script blocker enabled. No other versions or plugins are listed as vulnerable.

Risk and Exploitability

The CVSS score is 7.2, which represents a high severity. The EPSS score is below 1 %, indicating that exploitation is considered unlikely at this time, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through unauthenticated comment posting, requiring the comment to be approved by an administrator before the script is visible to site visitors. Successful exploitation would result in the execution of arbitrary JavaScript within the context of site users.

Generated by OpenCVE AI on September 19, 2026 at 20:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Complianz GDPR/CCPA Cookie Consent Banner plugin to the latest version (7.5.5 or later) to apply the vendor patch.
  • Temporarily disable the Twitter or Facebook cookie/script blocker in Complianz settings to eliminate the stored XSS path until an upgrade is possible.
  • Configure WordPress comment settings to restrict or block comment posting by unauthenticated users, or require administrator approval before comments are published.

Generated by OpenCVE AI on September 19, 2026 at 20:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Complianz
Complianz complianz – Gdpr/ccpa Cookie Consent
Wordpress
Wordpress wordpress
Vendors & Products Complianz
Complianz complianz – Gdpr/ccpa Cookie Consent
Wordpress
Wordpress wordpress

Fri, 18 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description The Complianz GDPR/CCPA Cookie Consent Banner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via Elementor Cookie Blocker Regex in all versions up to, and including, 7.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires an administrator to approve the attacker's comment, and the site must have both the Elementor plugin installed and Complianz configured with the Twitter or Facebook cookie/script blocker enabled.
Title Complianz GDPR/CCPA Cookie Consent Banner <= 7.5.4 - Unauthenticated Stored Cross-Site Scripting via Elementor Cookie Blocker Regex
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Complianz Complianz – Gdpr/ccpa Cookie Consent
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-18T10:46:24.429Z

Reserved: 2026-08-31T18:50:34.022Z

Link: CVE-2026-83561

cve-icon Vulnrichment

Updated: 2026-09-18T10:46:14.134Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T09:16:42.357

Modified: 2026-09-18T13:23:37.403

Link: CVE-2026-83561

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:15:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')