# WPConsent <= 1.1.9 - Unauthenticated Stored Cross-Site Scripting via Comments

- **ID:** WPSEC-2026-0687
- **Plugin:** WPConsent – Cookie Banner & Cookie Consent for Privacy Compliance (GDPR / CCPA / EU Compliance Cookie Notice) (`wpconsent-cookies-banner-privacy-suite`), https://wordpress.org/plugins/wpconsent-cookies-banner-privacy-suite/
- **Affected versions:** all versions before 1.2.0
- **Fixed in:** 1.2.0 (Update to 1.2.0 or later.)
- **Severity:** Medium 5.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N)
- **Weakness:** CWE-79
- **Usage among sites WPSec scans:** plugin Medium, affected versions Medium (as of 2026-10-10)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/wpconsent-cookies-banner-privacy-suite
- **Fix released:** 2026-10-08
- **Published:** 2026-10-10
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0687/

## Description

The WPConsent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted comments in all versions up to, and including, 1.1.9. This is due to the bundled HTML parser used by the Automatic Script Blocking feature shielding script, style, code bodies, comments, CDATA and server-side blocks with predictable placeholder keys ('___noise___' plus a four-digit counter starting at 1000) and blindly restoring any matching string found anywhere in the page, including content a visitor supplied (such as a comment). This makes it possible for unauthenticated attackers to inject text that matches a placeholder key so it is replaced at output time with the raw, unescaped contents of a shielded span (e.g. a script body) from elsewhere on the page, which then executes in the browser of any visitor to the affected page. Exploitation requires the Automatic Script Blocking feature (enabled by default) to be active.

## References

- https://wpsec.com/vuln/WPSEC-2026-0687/
- https://plugins.svn.wordpress.org/wpconsent-cookies-banner-privacy-suite/tags/1.2.0/
- https://wordpress.org/plugins/wpconsent-cookies-banner-privacy-suite/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0687/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
