Stored Cross-Site Scripting Vulnerability in iubenda Cookie Consent Plugin for WordPress
CVE-2026-77233

7.2HIGH

What is CVE-2026-77233?

The iubenda plugin for WordPress allows unauthenticated attackers to exploit a vulnerability related to stored cross-site scripting via comment content. This issue, arising from inadequate input sanitization and output escaping, targets versions up to 3.13.4 when the 'Secondary' parser engine is active. When exploited, attackers can inject arbitrary web scripts, which execute whenever a user accesses affected pages. It is important to note that the vulnerability is mitigated when the default 'new' DOM-based parser engine is enabled.

Affected Version(s)

iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more 0 <= 3.13.4

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pham Duc Anh
.