Stored XSS Vulnerability in Dourou Cookie Warning Plugin for WordPress
CVE-2025-49428
5.9MEDIUM
What is CVE-2025-49428?
The Dourou Cookie Warning plugin for WordPress exhibits a stored Cross-site Scripting (XSS) vulnerability due to improper handling of input during web page generation. This flaw allows an attacker to inject malicious scripts, which can be executed whenever a user accesses affected pages. Users with versions prior to 1.3 are advised to update to mitigate this security risk.
Affected Version(s)
Cookie Warning <= 1.3