<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cve-2026-92977 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/cve-2026-92977/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 03 Oct 2026 04:53:33 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/cve-2026-92977/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored XSS in The Real Cookie Banner WordPress Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-real-cookie-banner-xss/</link><pubDate>Sat, 03 Oct 2026 04:53:33 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-real-cookie-banner-xss/</guid><description>The Real Cookie Banner plugin (&lt;= 5.3.5) for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) via inadequate input sanitization in comment anchor tags, allowing unauthenticated attackers to execute arbitrary scripts in the browser context of site visitors.</description><content:encoded><![CDATA[<p>The Real Cookie Banner: GDPR &amp; ePrivacy Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) in all versions up to and including 5.3.5. The vulnerability stems from insufficient input sanitization and output escaping when handling content within comment anchor tags. Unauthenticated attackers can inject malicious payloads into the title attribute of these tags, which successfully bypass the default WordPress comment kses filter.</p>
<p>The exploitation relies on the plugin's internal rendering logic, specifically a page-wide regex operation that strips the closing quote delimiter of the title attribute at render time. This transformation converts the payload from a benign attribute value into executable HTML. While the exploitation requires the injected comment to survive the site's standard comment moderation workflow, successful execution allows attackers to run arbitrary scripts in the session of any user viewing the page, potentially leading to session hijacking, site defacement, or administrative account compromise if viewed by privileged users.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker crafts a malicious payload containing an XSS vector within the title attribute of an anchor tag (e.g., <code>&lt;a title='x' onmouseover=alert(1) '&gt;</code>).</li>
<li>Attacker submits the payload through the WordPress comment form.</li>
<li>The WordPress 'kses' filter processes the comment but fails to properly sanitize the title attribute of the anchor tag, allowing the payload to be saved to the database.</li>
<li>The malicious comment enters the site's moderation queue awaiting approval.</li>
<li>An administrator or moderator reviews and approves the malicious comment, moving it to a public-facing page.</li>
<li>A target user visits the page containing the malicious comment.</li>
<li>The Real Cookie Banner plugin processes the page, and its regex strips the closing quote delimiter of the title attribute.</li>
<li>The malicious script is rendered as valid HTML in the victim's browser and executes with the privileges of the victim's session.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows for the execution of arbitrary JavaScript in the context of the victim's browser session. If a site administrator views a page containing the malicious payload, the attacker could potentially perform actions on behalf of the administrator, lead to unauthorized configuration changes, or exfiltrate sensitive site data. The vulnerability affects any WordPress site running the vulnerable version of the Real Cookie Banner plugin that permits user comments.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the update of the Real Cookie Banner: GDPR &amp; ePrivacy Cookie Consent plugin to the latest available version beyond 5.3.5 to mitigate CVE-2026-92977. Ensure that the WordPress comment moderation workflow is configured to require manual approval for all comments to prevent unauthenticated injection attempts from immediately becoming publicly visible. Conduct a review of recently approved comments for any suspicious anchor tag attributes.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-application</category><category>xss</category><category>wordpress</category><category>cve-2026-92977</category></item></channel></rss>