{
 "id": "WPSEC-2026-0687",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0687/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0687/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0687/index.md",
 "title": "WPConsent <= 1.1.9 - Unauthenticated Stored Cross-Site Scripting via Comments",
 "description": "The WPConsent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted comments in all versions up to, and including, 1.1.9. This is due to the bundled HTML parser used by the Automatic Script Blocking feature shielding script, style, code bodies, comments, CDATA and server-side blocks with predictable placeholder keys ('___noise___' plus a four-digit counter starting at 1000) and blindly restoring any matching string found anywhere in the page, including content a visitor supplied (such as a comment). This makes it possible for unauthenticated attackers to inject text that matches a placeholder key so it is replaced at output time with the raw, unescaped contents of a shielded span (e.g. a script body) from elsewhere on the page, which then executes in the browser of any visitor to the affected page. Exploitation requires the Automatic Script Blocking feature (enabled by default) to be active.",
 "plugin": {
  "slug": "wpconsent-cookies-banner-privacy-suite",
  "name": "WPConsent",
  "full_name": "WPConsent – Cookie Banner & Cookie Consent for Privacy Compliance (GDPR / CCPA / EU Compliance Cookie Notice)",
  "wordpress_org": "https://wordpress.org/plugins/wpconsent-cookies-banner-privacy-suite/",
  "advisories_url": "https://wpsec.com/vuln/plugin/wpconsent-cookies-banner-privacy-suite/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/wpconsent-cookies-banner-privacy-suite"
 },
 "type": "XSS",
 "cwe": [
  "CWE-79"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 5.4,
  "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "1.2.0",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 1.2.0"
  ]
 },
 "introduced_in": null,
 "fixed_in": "1.2.0",
 "remediation": "Update to 1.2.0 or later.",
 "fix_released": "2026-10-08T11:29:05+00:00",
 "published": "2026-10-10T15:41:27+00:00",
 "updated": "2026-10-10T14:52:55.515646+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0687/",
  "https://plugins.svn.wordpress.org/wpconsent-cookies-banner-privacy-suite/tags/1.2.0/",
  "https://wordpress.org/plugins/wpconsent-cookies-banner-privacy-suite/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/wpconsent-cookies-banner-privacy-suite",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Medium",
  "affected_versions": "Medium",
  "as_of": "2026-10-10"
 }
}