Back

MEDIUM

GDPR Cookie Consent <= 2.6.0 - Unauthenticated Stored XSS

Published May 15, 2025

Description

The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not properly sanitize and escape the IP headers when logging them, allowing visitors to conduct Stored Cross-Site Scripting attacks. The payload gets triggered when an admin visits the 'Consent report' page and the malicious script is executed in the admin context.

Affected products

Remediation

No remediation recorded yet.

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WPScan
Published May 15, 2025
Updated May 17, 2025
Reserved Sep 3, 2024
CISA Vulnrichment
Updated May 17, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a