{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/the-real-cookie-banner-gdpr--eprivacy-cookie-consent--5.3.5/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wordpress:the_real_cookie_banner_gdpr_eprivacy_cookie_consent:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-92977"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["The Real Cookie Banner: GDPR \u0026 ePrivacy Cookie Consent (\u003c= 5.3.5)"],"_cs_severities":["high"],"_cs_tags":["web-application","xss","wordpress","cve-2026-92977"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Real Cookie Banner: GDPR \u0026amp; ePrivacy Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) in all versions up to and including 5.3.5. The vulnerability stems from insufficient input sanitization and output escaping when handling content within comment anchor tags. Unauthenticated attackers can inject malicious payloads into the title attribute of these tags, which successfully bypass the default WordPress comment kses filter.\u003c/p\u003e\n\u003cp\u003eThe exploitation relies on the plugin's internal rendering logic, specifically a page-wide regex operation that strips the closing quote delimiter of the title attribute at render time. This transformation converts the payload from a benign attribute value into executable HTML. While the exploitation requires the injected comment to survive the site's standard comment moderation workflow, successful execution allows attackers to run arbitrary scripts in the session of any user viewing the page, potentially leading to session hijacking, site defacement, or administrative account compromise if viewed by privileged users.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker crafts a malicious payload containing an XSS vector within the title attribute of an anchor tag (e.g., \u003ccode\u003e\u0026lt;a title='x' onmouseover=alert(1) '\u0026gt;\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eAttacker submits the payload through the WordPress comment form.\u003c/li\u003e\n\u003cli\u003eThe WordPress 'kses' filter processes the comment but fails to properly sanitize the title attribute of the anchor tag, allowing the payload to be saved to the database.\u003c/li\u003e\n\u003cli\u003eThe malicious comment enters the site's moderation queue awaiting approval.\u003c/li\u003e\n\u003cli\u003eAn administrator or moderator reviews and approves the malicious comment, moving it to a public-facing page.\u003c/li\u003e\n\u003cli\u003eA target user visits the page containing the malicious comment.\u003c/li\u003e\n\u003cli\u003eThe Real Cookie Banner plugin processes the page, and its regex strips the closing quote delimiter of the title attribute.\u003c/li\u003e\n\u003cli\u003eThe malicious script is rendered as valid HTML in the victim's browser and executes with the privileges of the victim's session.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows for the execution of arbitrary JavaScript in the context of the victim's browser session. If a site administrator views a page containing the malicious payload, the attacker could potentially perform actions on behalf of the administrator, lead to unauthorized configuration changes, or exfiltrate sensitive site data. The vulnerability affects any WordPress site running the vulnerable version of the Real Cookie Banner plugin that permits user comments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the update of the Real Cookie Banner: GDPR \u0026amp; ePrivacy Cookie Consent plugin to the latest available version beyond 5.3.5 to mitigate CVE-2026-92977. Ensure that the WordPress comment moderation workflow is configured to require manual approval for all comments to prevent unauthenticated injection attempts from immediately becoming publicly visible. Conduct a review of recently approved comments for any suspicious anchor tag attributes.\u003c/p\u003e\n","date_modified":"2026-10-03T04:53:33Z","date_published":"2026-10-03T04:53:33Z","id":"https://feed.craftedsignal.io/briefs/2026-10-real-cookie-banner-xss/","summary":"The Real Cookie Banner plugin (\u003c= 5.3.5) for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) via inadequate input sanitization in comment anchor tags, allowing unauthenticated attackers to execute arbitrary scripts in the browser context of site visitors.","title":"Stored XSS in The Real Cookie Banner WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-real-cookie-banner-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - The Real Cookie Banner: GDPR \u0026 EPrivacy Cookie Consent (\u003c= 5.3.5)","version":"https://jsonfeed.org/version/1.1"}