WPConsent <= 1.1.9 - Unauthenticated Stored Cross-Site Scripting via Comments
- ID
- WPSEC-2026-0687
- Plugin
- WPConsent – Cookie Banner & Cookie Consent for Privacy Compliance (GDPR / CCPA / EU Compliance Cookie Notice) (wpconsent-cookies-banner-privacy-suite)
- Affected
- all versions before 1.2.0
- Remediation
- Update to 1.2.0 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
- Weakness
- CWE-79
- Usage
- Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-10
- Attack surface
- WPConsent on WPSec AttackSurface
- Fix released
- Published
Description
The WPConsent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted comments in all versions up to, and including, 1.1.9. This is due to the bundled HTML parser used by the Automatic Script Blocking feature shielding script, style, code bodies, comments, CDATA and server-side blocks with predictable placeholder keys ('___noise___' plus a four-digit counter starting at 1000) and blindly restoring any matching string found anywhere in the page, including content a visitor supplied (such as a comment). This makes it possible for unauthenticated attackers to inject text that matches a placeholder key so it is replaced at output time with the raw, unescaped contents of a shielded span (e.g. a script body) from elsewhere on the page, which then executes in the browser of any visitor to the affected page. Exploitation requires the Automatic Script Blocking feature (enabled by default) to be active.
References
- https://wpsec.com/vuln/WPSEC-2026-0687/
- https://plugins.svn.wordpress.org/wpconsent-cookies-banner-privacy-suite/tags/1.2.0/
- https://wordpress.org/plugins/wpconsent-cookies-banner-privacy-suite/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS