{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/all-in-one-compliance-for-gdpr-/-ccpa-cookie-consent-+-more--3.13.4/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:iubenda:all-in-one_compliance_for_gdpr_/_ccpa_cookie_consent_%2B_more:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-77233"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["All-in-one Compliance for GDPR / CCPA Cookie Consent + more (\u003c= 3.13.4)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","xss","wordpress"],"_cs_type":"advisory","_cs_vendors":["iubenda"],"content_html":"\u003cp\u003eThe iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) in versions up to and including 3.13.4. The vulnerability arises from insufficient input sanitization and output escaping within the plugin's handling of comment content via the AdSense Regex Rewrite functionality. This flaw is specifically triggered when the 'Secondary' parser engine is active (parser_engine=default).\u003c/p\u003e\n\u003cp\u003eUnauthenticated attackers can exploit this by submitting specially crafted comment content that includes malicious JavaScript. When an administrator or other user views the affected page where the injected comment is rendered, the script executes within the context of their session. This can lead to session hijacking, unauthorized actions performed on behalf of the victim, or credential theft. The vulnerability does not exist when the default 'new' DOM-based parser engine is in use, making it critical for administrators to verify their parser configuration and update the plugin.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe successful exploitation of this vulnerability allows unauthenticated attackers to execute arbitrary JavaScript in the browser of any user viewing the injected content. This poses a significant risk to the integrity and confidentiality of user sessions, particularly those of administrative users who frequently interact with site comments and moderation panels. If an administrator is targeted, the attacker could potentially take full control of the WordPress instance.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more plugin to the latest version immediately.\u003c/li\u003e\n\u003cli\u003eReview plugin settings in the WordPress dashboard to ensure the 'Secondary' parser engine is disabled, or switch to the 'new' DOM-based parser engine if possible.\u003c/li\u003e\n\u003cli\u003eMonitor web application firewall logs for common XSS payloads (e.g., \u0026lt;script\u0026gt;, onload=, onerror=) directed at WordPress comment submission endpoints.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-05T07:30:06Z","date_published":"2026-09-05T07:30:06Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-77233-xss/","summary":"The iubenda All-in-one Compliance for GDPR / CCPA Cookie Consent plugin for WordPress contains a stored XSS vulnerability in versions 3.13.4 and earlier, allowing unauthenticated attackers to inject malicious scripts when the Secondary parser engine is enabled.","title":"Stored Cross-Site Scripting in iubenda WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-77233-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - All-in-One Compliance for GDPR / CCPA Cookie Consent + More (\u003c= 3.13.4)","version":"https://jsonfeed.org/version/1.1"}