Vulnerabilities / WPConsent / WPSEC-2026-0687

WPConsent <= 1.1.9 - Unauthenticated Stored Cross-Site Scripting via Comments

Medium 5.4 CWE-79Fixed in 1.2.0
ID
WPSEC-2026-0687
Plugin
WPConsent – Cookie Banner & Cookie Consent for Privacy Compliance (GDPR / CCPA / EU Compliance Cookie Notice) (wpconsent-cookies-banner-privacy-suite)
Affected
all versions before 1.2.0
Remediation
Update to 1.2.0 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
Weakness
CWE-79
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-10
Attack surface
WPConsent on WPSec AttackSurface
Fix released
Published

Description

The WPConsent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted comments in all versions up to, and including, 1.1.9. This is due to the bundled HTML parser used by the Automatic Script Blocking feature shielding script, style, code bodies, comments, CDATA and server-side blocks with predictable placeholder keys ('___noise___' plus a four-digit counter starting at 1000) and blindly restoring any matching string found anywhere in the page, including content a visitor supplied (such as a comment). This makes it possible for unauthenticated attackers to inject text that matches a placeholder key so it is replaced at output time with the raw, unescaped contents of a shielded span (e.g. a script body) from elsewhere on the page, which then executes in the browser of any visitor to the affected page. Exploitation requires the Automatic Script Blocking feature (enabled by default) to be active.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0