Stored XSS in The Real Cookie Banner WordPress Plugin
The Real Cookie Banner plugin (<= 5.3.5) for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) via inadequate input sanitization in comment anchor tags, allowing unauthenticated attackers to execute arbitrary scripts in the browser context of site visitors.
CVE search metadata
CVE search record: CVE-2026-92977. Severity: high. CVSS: 7.2. KEV: no. Product: The Real Cookie Banner: GDPR & ePrivacy Cookie Consent (<= 5.3.5). Brief: Stored XSS in The Real Cookie Banner WordPress Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-real-cookie-banner-xss/
The Real Cookie Banner: GDPR & ePrivacy Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) in all versions up to and including 5.3.5. The vulnerability stems from insufficient input sanitization and output escaping when handling content within comment anchor tags. Unauthenticated attackers can inject malicious payloads into the title attribute of these tags, which successfully bypass the default WordPress comment kses filter.
The exploitation relies on the plugin's internal rendering logic, specifically a page-wide regex operation that strips the closing quote delimiter of the title attribute at render time. This transformation converts the payload from a benign attribute value into executable HTML. While the exploitation requires the injected comment to survive the site's standard comment moderation workflow, successful execution allows attackers to run arbitrary scripts in the session of any user viewing the page, potentially leading to session hijacking, site defacement, or administrative account compromise if viewed by privileged users.
Attack Chain
- Attacker crafts a malicious payload containing an XSS vector within the title attribute of an anchor tag (e.g.,
<a title='x' onmouseover=alert(1) '>). - Attacker submits the payload through the WordPress comment form.
- The WordPress 'kses' filter processes the comment but fails to properly sanitize the title attribute of the anchor tag, allowing the payload to be saved to the database.
- The malicious comment enters the site's moderation queue awaiting approval.
- An administrator or moderator reviews and approves the malicious comment, moving it to a public-facing page.
- A target user visits the page containing the malicious comment.
- The Real Cookie Banner plugin processes the page, and its regex strips the closing quote delimiter of the title attribute.
- The malicious script is rendered as valid HTML in the victim's browser and executes with the privileges of the victim's session.
Impact
Successful exploitation of this vulnerability allows for the execution of arbitrary JavaScript in the context of the victim's browser session. If a site administrator views a page containing the malicious payload, the attacker could potentially perform actions on behalf of the administrator, lead to unauthorized configuration changes, or exfiltrate sensitive site data. The vulnerability affects any WordPress site running the vulnerable version of the Real Cookie Banner plugin that permits user comments.
Recommendation
Prioritize the update of the Real Cookie Banner: GDPR & ePrivacy Cookie Consent plugin to the latest available version beyond 5.3.5 to mitigate CVE-2026-92977. Ensure that the WordPress comment moderation workflow is configured to require manual approval for all comments to prevent unauthenticated injection attempts from immediately becoming publicly visible. Conduct a review of recently approved comments for any suspicious anchor tag attributes.
Immediate actions
Update The Real Cookie Banner plugin to the latest version.
Mitigations
Enable strict comment moderation settings to review all incoming comments.
CVE-2026-92977