{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/complianz/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-83561"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Complianz GDPR/CCPA Cookie Consent Banner (\u003c= 7.5.4)","Elementor"],"_cs_severities":["high"],"_cs_tags":["wordpress","xss","web-application"],"_cs_type":"advisory","_cs_vendors":["Complianz","Elementor"],"content_html":"\u003cp\u003eThe Complianz GDPR/CCPA Cookie Consent Banner plugin for WordPress (versions 7.5.4 and below) contains a Stored Cross-Site Scripting (XSS) vulnerability. The issue stems from insufficient input sanitization and output escaping within the plugin's Elementor Cookie Blocker component. An unauthenticated attacker can inject malicious JavaScript into comment fields. The script is stored and subsequently executed when a site administrator approves the comment. For exploitation to succeed, the target site must have the Elementor plugin installed and the Complianz plugin configured to use the Twitter or Facebook cookie/script blocker regex features. This vulnerability represents a significant risk for administrative account takeover or session hijacking if an administrator views the malicious content.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the execution of arbitrary JavaScript within the session of an authenticated administrator. This can lead to unauthorized actions performed on behalf of the administrator, data exfiltration, or the creation of new administrative accounts if the site configuration permits. The vulnerability affects all users running versions up to and including 7.5.4.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade the Complianz GDPR/CCPA Cookie Consent Banner plugin to the latest version (post-7.5.4) as soon as a patch is available.\u003c/li\u003e\n\u003cli\u003eImplement strict Content Security Policy (CSP) headers to mitigate the impact of XSS by restricting the sources from which scripts can be loaded and executed.\u003c/li\u003e\n\u003cli\u003eReview and audit pending comments for suspicious content containing script tags or abnormal HTML attributes prior to approval.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-18T10:06:13Z","date_published":"2026-09-18T10:06:13Z","id":"https://feed.craftedsignal.io/briefs/2026-09-complianz-xss/","summary":"The Complianz GDPR/CCPA Cookie Consent Banner plugin is vulnerable to Stored Cross-Site Scripting (XSS) via the Elementor Cookie Blocker, allowing attackers to execute arbitrary JavaScript in the context of an administrator-approved comment.","title":"Stored XSS Vulnerability in Complianz WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-complianz-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Complianz","version":"https://jsonfeed.org/version/1.1"}