Stored Cross-Site Scripting Vulnerability in Real Cookie Banner Plugin by WordPress
CVE-2025-1485
What is CVE-2025-1485?
The Real Cookie Banner: GDPR & ePrivacy Cookie Consent plugin for WordPress, including the premium real-cookie-banner-pro version, is prone to a stored cross-site scripting vulnerability due to inadequate sanitization and escaping of certain settings. This flaw enables users with high privilege access, such as administrators, to execute malicious scripts. This risk remains even when the unfiltered_html capability is disabled, particularly in multisite setups, which can lead to serious implications for the site's security and data integrity.
Affected Version(s)
Real Cookie Banner: GDPR & ePrivacy Cookie Consent 0 < 5.1.6
real-cookie-banner-pro 0 < 5.1.6
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved