Impact
The Real Cookie Banner plugin contains a stored XSS vulnerability that permits any unauthenticated user to insert malicious scripts through comments. The flaw arises from inadequate sanitization of the comment title attribute, which WordPress’ filter does not strip at save time. When the comment is rendered, the plugin’s regular expression removes a closing quote, converting the payload into a valid attribute value and allowing the script to execute in the context of the user’s browser. This could lead to session hijacking, defacement, or data exfiltration on any site using the plugin.
Affected Systems
The vulnerability affects every instance of the devowl Real Cookie Banner: GDPR & ePrivacy Cookie Consent plugin for WordPress, in all versions up to and including 5.3.5. No specific revisions beyond the mentioned cutoff are listed, so any site running this plugin edition is potentially impacted.
Risk and Exploitability
The issue carries a CVSS score of 7.2, indicating a high severity that requires attention. Because the attack can be performed over the public Internet and does not require privileged access or user interaction beyond comment posting, the risk is considerable. The EPSS score is not available, but the exploitability is clear from the description: an attacker can submit a comment, wait for moderation approval, and then the injected script will run for any visitor to the affected pages. The vulnerability is not listed in the CISA KEV catalog, yet the potential impact warrants prompt remediation.
OpenCVE Enrichment