<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>All-in-One Compliance for GDPR / CCPA Cookie Consent + More (&lt;= 3.13.4) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/all-in-one-compliance-for-gdpr-/-ccpa-cookie-consent-+-more--3.13.4/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 05 Sep 2026 07:30:06 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/all-in-one-compliance-for-gdpr-/-ccpa-cookie-consent-+-more--3.13.4/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored Cross-Site Scripting in iubenda WordPress Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2026-77233-xss/</link><pubDate>Sat, 05 Sep 2026 07:30:06 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2026-77233-xss/</guid><description>The iubenda All-in-one Compliance for GDPR / CCPA Cookie Consent plugin for WordPress contains a stored XSS vulnerability in versions 3.13.4 and earlier, allowing unauthenticated attackers to inject malicious scripts when the Secondary parser engine is enabled.</description><content:encoded><![CDATA[<p>The iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) in versions up to and including 3.13.4. The vulnerability arises from insufficient input sanitization and output escaping within the plugin's handling of comment content via the AdSense Regex Rewrite functionality. This flaw is specifically triggered when the 'Secondary' parser engine is active (parser_engine=default).</p>
<p>Unauthenticated attackers can exploit this by submitting specially crafted comment content that includes malicious JavaScript. When an administrator or other user views the affected page where the injected comment is rendered, the script executes within the context of their session. This can lead to session hijacking, unauthorized actions performed on behalf of the victim, or credential theft. The vulnerability does not exist when the default 'new' DOM-based parser engine is in use, making it critical for administrators to verify their parser configuration and update the plugin.</p>
<h2 id="impact">Impact</h2>
<p>The successful exploitation of this vulnerability allows unauthenticated attackers to execute arbitrary JavaScript in the browser of any user viewing the injected content. This poses a significant risk to the integrity and confidentiality of user sessions, particularly those of administrative users who frequently interact with site comments and moderation panels. If an administrator is targeted, the attacker could potentially take full control of the WordPress instance.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update the iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more plugin to the latest version immediately.</li>
<li>Review plugin settings in the WordPress dashboard to ensure the 'Secondary' parser engine is disabled, or switch to the 'new' DOM-based parser engine if possible.</li>
<li>Monitor web application firewall logs for common XSS payloads (e.g., &lt;script&gt;, onload=, onerror=) directed at WordPress comment submission endpoints.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-vulnerability</category><category>xss</category><category>wordpress</category></item></channel></rss>