Description
The Real Cookie Banner: GDPR & ePrivacy Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment in all versions up to, and including, 5.3.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Malicious script payloads placed in the title attribute of an anchor tag survive WordPress's comment kses filter at save time, as the payload is only promoted to executable HTML attributes when the plugin's page-wide regex strips the closing quote delimiter at render time; exploitability is therefore subject to the standard comment moderation workflow before the comment is publicly displayed.
Published: 2026-10-03
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting (XSS) enabling arbitrary script execution on pages viewed by any user
Action: Apply Patch
AI Analysis

Impact

The Real Cookie Banner plugin contains a stored XSS vulnerability that permits any unauthenticated user to insert malicious scripts through comments. The flaw arises from inadequate sanitization of the comment title attribute, which WordPress’ filter does not strip at save time. When the comment is rendered, the plugin’s regular expression removes a closing quote, converting the payload into a valid attribute value and allowing the script to execute in the context of the user’s browser. This could lead to session hijacking, defacement, or data exfiltration on any site using the plugin.

Affected Systems

The vulnerability affects every instance of the devowl Real Cookie Banner: GDPR & ePrivacy Cookie Consent plugin for WordPress, in all versions up to and including 5.3.5. No specific revisions beyond the mentioned cutoff are listed, so any site running this plugin edition is potentially impacted.

Risk and Exploitability

The issue carries a CVSS score of 7.2, indicating a high severity that requires attention. Because the attack can be performed over the public Internet and does not require privileged access or user interaction beyond comment posting, the risk is considerable. The EPSS score is not available, but the exploitability is clear from the description: an attacker can submit a comment, wait for moderation approval, and then the injected script will run for any visitor to the affected pages. The vulnerability is not listed in the CISA KEV catalog, yet the potential impact warrants prompt remediation.

Generated by OpenCVE AI on October 3, 2026 at 04:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Real Cookie Banner plugin to version 5.3.6 or later, ensuring the sanitization fix is applied
  • If immediate upgrade is not possible, remove or heavily sanitize the comment title attribute before rendering or disable the comment feature on pages where the plugin is used
  • Review existing comments to locate and delete any stored malicious scripts, and implement a routine audit of comment content to prevent future injections

Generated by OpenCVE AI on October 3, 2026 at 04:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 03 Oct 2026 03:45:00 +0000

Type Values Removed Values Added
Description The Real Cookie Banner: GDPR & ePrivacy Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment in all versions up to, and including, 5.3.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Malicious script payloads placed in the title attribute of an anchor tag survive WordPress's comment kses filter at save time, as the payload is only promoted to executable HTML attributes when the plugin's page-wide regex strips the closing quote delimiter at render time; exploitability is therefore subject to the standard comment moderation workflow before the comment is publicly displayed.
Title Real Cookie Banner: GDPR & ePrivacy Cookie Consent <= 5.3.5 - Unauthenticated Stored Cross-Site Scripting via Comment
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-03T15:42:46.548Z

Reserved: 2026-09-17T13:40:47.054Z

Link: CVE-2026-92977

cve-icon Vulnrichment

Updated: 2026-10-03T15:39:40.128Z

cve-icon NVD

Status : Received

Published: 2026-10-03T04:18:04.190

Modified: 2026-10-03T16:16:43.923

Link: CVE-2026-92977

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T04:30:19Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')