{
 "id": "WPSEC-2026-0727",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0727/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0727/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0727/index.md",
 "title": "Record of Consent Extension for Complianz <= 2.5 - Unauthenticated Stored Cross-Site Scripting via 'uid' Parameter",
 "description": "The Record of Consent Extension for Complianz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'uid' parameter of the public consent-recording AJAX action (rocext_custom_store) in all versions up to, and including, 2.5, due to insufficient input validation (the value is only passed through sanitize_text_field(), which keeps quotes) and insufficient output escaping in the admin inline label editor, which builds HTML attributes from the stored user ID without encoding quotes. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute when an administrator opens the inline label editor for the injected record on the plugin's Records tab.",
 "plugin": {
  "slug": "record-of-consent-extension-for-complianz",
  "name": "Record of Consent Extension for Complianz",
  "full_name": "Record of Consent Extension for Complianz",
  "wordpress_org": "https://wordpress.org/plugins/record-of-consent-extension-for-complianz/",
  "advisories_url": "https://wpsec.com/vuln/plugin/record-of-consent-extension-for-complianz/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/record-of-consent-extension-for-complianz"
 },
 "type": "XSS",
 "cwe": [
  "CWE-79"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 6.1,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "2.6",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 2.6"
  ]
 },
 "introduced_in": null,
 "fixed_in": "2.6",
 "remediation": "Update to 2.6 or later.",
 "fix_released": "2026-10-09T11:22:46+00:00",
 "published": "2026-10-10T15:41:27+00:00",
 "updated": "2026-10-10T14:53:42.230523+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0727/",
  "https://plugins.svn.wordpress.org/record-of-consent-extension-for-complianz/tags/2.6/",
  "https://wordpress.org/plugins/record-of-consent-extension-for-complianz/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/record-of-consent-extension-for-complianz",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-10"
 }
}