Record of Consent Extension for Complianz <= 2.5 - Unauthenticated Stored Cross-Site Scripting via 'uid' Parameter
- ID
- WPSEC-2026-0727
- Plugin
- Record of Consent Extension for Complianz (record-of-consent-extension-for-complianz)
- Affected
- all versions before 2.6
- Remediation
- Update to 2.6 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Weakness
- CWE-79
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-10
- Attack surface
- Record of Consent Extension for Complianz on WPSec AttackSurface
- Fix released
- Published
Description
The Record of Consent Extension for Complianz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'uid' parameter of the public consent-recording AJAX action (rocext_custom_store) in all versions up to, and including, 2.5, due to insufficient input validation (the value is only passed through sanitize_text_field(), which keeps quotes) and insufficient output escaping in the admin inline label editor, which builds HTML attributes from the stored user ID without encoding quotes. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute when an administrator opens the inline label editor for the injected record on the plugin's Records tab.
References
- https://wpsec.com/vuln/WPSEC-2026-0727/
- https://plugins.svn.wordpress.org/record-of-consent-extension-for-complianz/tags/2.6/
- https://wordpress.org/plugins/record-of-consent-extension-for-complianz/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS