Sceawere

Vulnerability Detail

CVE-2026-73359UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

WP Cookie Notice Subscriber XSS

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
3h ago
Vendor
WP Legal Pages
Product
WP Cookie Notice for GDPR, CCPA & ePrivacy Consent
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Subscriber Cross Site Scripting (XSS) in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.3.9 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-08-18T15:17:04.217Z",
  "pubdate": "2026-08-18T15:17:04.217Z",
  "executiveSummary": "A Cross-Site Scripting (XSS) vulnerability exists in the WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin in versions up to and including 4.3.9. This security flaw enables authenticated users with subscriber-level privileges or higher to inject malicious JavaScript payloads into the application, which are subsequently executed within the context of other administrative or privileged user sessions when viewing the affected components.\nThe vulnerability exposes systems to severe security implications, notably session hijacking, unauthorized data access, and unauthorized administrative actions performed via the victim's browser. Successful exploitation requires an attacker to authenticate with subscriber privileges on the target WordPress installation and interact with the vulnerable input handling mechanisms.\nThe risk profile of this vulnerability is moderate to high depending on the site configuration, as it bridges the gap between low-privileged subscriber accounts and administrative compromise through Stored or Reflected XSS vectors inherent to the flawed parameter handling of the plugin.",
  "technicalDetails": "The vulnerability stems from improper input sanitization and output encoding within the WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin <= 4.3.9. When handling user-supplied data intended for storage or immediate reflection within the WordPress administrative or front-end interfaces, the application fails to adequately neutralize HTML tags and JavaScript constructs. Consequently, input parameters processed by the plugin are rendered directly into the Document Object Model (DOM) without context-aware escaping.\nThe exploitation vector requires an attacker to possess at least subscriber-level access to the WordPress instance. The attack flow proceeds as follows: First, the authenticated attacker crafts a malicious HTTP request containing a payload consisting of arbitrary JavaScript encapsulated within HTML markup, such as script tags or event handlers (e.g., onerror, onload). Second, the attacker submits this payload to the vulnerable endpoint managed by the plugin. Third, the application processes the input and stores or reflects it improperly without applying rigorous sanitization routines.\nWhen a privileged user, such as an administrator, navigates to the compromised page or view where the payload is rendered, the browser parses the malicious script. The payload executes within the security context of the victim's active session, allowing the script to inherit the user's privileges. This facilitates post-exploitation activities including the execution of arbitrary administrative actions, creation of new backdoor accounts, extraction of sensitive cookies, or redirection of the user to malicious external resources.\nThe vulnerable component resides within the request handling and rendering logic of the WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin. Network exposure is standard web-based (HTTP/HTTPS), requiring network reachability to the WordPress site and valid subscriber credentials to initiate the attack sequence."
}
CVE-2026-73359: WP Cookie Notice Subscriber XSS (MEDIUM Severity, CVSS: 6.5) - Sceawere