Sceawere
Vulnerability Detail
CVE-2026-42636UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated XSS in Cookie Notice
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 16h ago
- Vendor
- WP Legal Pages
- Product
- WP Cookie Notice for GDPR, CCPA & ePrivacy Consent
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Cross Site Scripting (XSS) in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.4.6 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-10-06T09:17:55.333Z",
"pubdate": "2026-10-06T09:17:55.333Z",
"executiveSummary": "The WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin, in versions 4.4.6 and below, is susceptible to an unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability. This security flaw resides within the handling of user-supplied input that is improperly sanitized or encoded before being reflected back into the browser's Document Object Model (DOM).\nSuccessful exploitation allows a remote, unauthenticated attacker to inject malicious JavaScript into the client-side environment of unsuspecting users visiting the target WordPress site. The impact is significant, potentially leading to unauthorized actions performed on behalf of authenticated administrators, theft of session cookies, sensitive information disclosure, or the redirection of users to malicious third-party domains. Because the vulnerability does not require authentication, the attack surface is broad, encompassing any visitor who interacts with a crafted link or malicious trigger point. The risk implications include full compromise of administrative session integrity if the XSS is leveraged against privileged accounts, making it a critical threat to WordPress ecosystem security.",
"technicalDetails": "The vulnerability originates from improper input validation and output encoding within the WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin. Specifically, the affected code fails to sanitize parameters before reflecting them into the application's HTML response. This failure allows for the injection of arbitrary HTML and JavaScript tags into the DOM context of the victim's browser.\nThe exploitation flow begins when an attacker crafts a malicious URL containing a JavaScript payload within a vulnerable parameter. When an unauthenticated victim clicks the link, the server processes the input and returns a response containing the unencoded payload in the HTTP body. Because the browser interprets the returned content as part of the trusted origin, it executes the injected script within the security context of the target domain.\nThe lack of authentication requirements facilitates this attack, as the payload execution is triggered solely through the user's interaction with the malicious URL. The vulnerable component consists of the input processing logic associated with the cookie notice display or configuration parameters that lack sufficient output sanitization functions, such as esc_html() or esc_attr().\nOnce the payload executes, the post-exploitation impact depends on the nature of the script. Common vectors include hijacking administrator session cookies by accessing document.cookie, performing unauthorized administrative operations via background fetch/XHR requests, or modifying the site content to display phishing forms. The scope of exposure is limited only by the privileges of the user targeted by the XSS. For an administrator, this can lead to full site takeover through the modification of themes, plugin settings, or the creation of new administrative accounts. For standard users, this can lead to credential theft or persistent malware delivery. The vulnerability affects all versions up to and including 4.4.6, as the underlying codebase lacks the necessary filtering to thwart XSS vectors consistently."
}