Stored Cross-Site Scripting Vulnerability in iubenda Cookie Consent Plugin for WordPress
CVE-2026-77263
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 5 September 2026
What is CVE-2026-77263?
The iubenda Cookie Consent plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability that arises from inadequate input sanitization and escaping of output. This flaw allows unauthenticated attackers to insert malicious web scripts into comments, which are executed when users visit affected pages. By manipulating KSES-safe markup, the attacker can exploit the vulnerability and create executable elements in the WordPress environment. This not only jeopardizes user data but also poses significant risks to site integrity, affecting all visitors, including logged-in administrators.
Affected Version(s)
iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more 0 <= 3.13.4