{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/cookie-banner-for-gdpr-/-ccpa--wplp-cookie-consent/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-13360"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Cookie Banner for GDPR / CCPA – WPLP Cookie Consent"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["WPLP"],"content_html":"\u003cp\u003eThe Cookie Banner for GDPR / CCPA - WPLP Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) in versions up to and including 4.3.5. The flaw exists due to improper input sanitization and output escaping within the 'regionArray' parameter. The vulnerability manifests in two ways: unauthenticated attackers can inject arbitrary web scripts if the 'Support Google Consent Mode (GCM)' feature is enabled by the administrator, and authenticated users with low-level privileges (such as Subscribers) can overwrite plugin settings because the AJAX handler lacks nonce or capability verification. This vulnerability enables attackers to execute malicious scripts in the context of a victim's browser, potentially leading to session hijacking, credential theft, or unauthorized actions performed on behalf of the victim.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a WordPress site running an outdated version (\u0026lt;= 4.3.5) of the WPLP Cookie Consent plugin.\u003c/li\u003e\n\u003cli\u003eFor authenticated exploitation, the attacker logs in as a low-privilege user (Subscriber).\u003c/li\u003e\n\u003cli\u003eThe attacker sends a crafted AJAX request to the vulnerable plugin handler, targeting the 'regionArray' parameter.\u003c/li\u003e\n\u003cli\u003eThe plugin fails to validate the request origin (no nonce) or user permissions (no capability check).\u003c/li\u003e\n\u003cli\u003eThe malicious script is saved into the database as part of the plugin configuration.\u003c/li\u003e\n\u003cli\u003eThe attacker waits for a high-privilege user or administrator to navigate to a page where the cookie banner is rendered.\u003c/li\u003e\n\u003cli\u003eThe victim's browser fetches the malicious script from the database and renders it, leading to arbitrary JavaScript execution in the victim's session.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows attackers to execute arbitrary JavaScript in the victim's browser session. This can lead to the exfiltration of session cookies, administrative actions taken without user consent, or the redirection of users to malicious websites. As the plugin is used for GDPR and CCPA compliance, it is widely deployed on public-facing websites, increasing the potential impact to both site administrators and site visitors.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the Cookie Banner for GDPR / CCPA - WPLP Cookie Consent plugin to the latest patched version immediately.\u003c/li\u003e\n\u003cli\u003eReview WordPress application logs for unusual AJAX requests targeting plugin settings or the 'regionArray' parameter.\u003c/li\u003e\n\u003cli\u003eIf immediate patching is not possible, disable the 'Support Google Consent Mode (GCM)' setting in the plugin configuration as a temporary mitigation.\u003c/li\u003e\n\u003cli\u003eMonitor for unauthorized administrative actions originating from low-privilege (Subscriber) accounts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-15T06:16:40Z","date_published":"2026-08-15T06:16:40Z","id":"https://feed.craftedsignal.io/briefs/2026-08-wplp-xss/","summary":"The WPLP Cookie Consent plugin for WordPress is vulnerable to stored cross-site scripting due to insufficient input validation in the regionArray parameter, allowing script injection by authenticated or unauthenticated attackers.","title":"Stored XSS Vulnerability in Cookie Banner for GDPR / CCPA Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-wplp-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Cookie Banner for GDPR / CCPA – WPLP Cookie Consent","version":"https://jsonfeed.org/version/1.1"}