CVE-2025-1619: GDPR Cookie Compliance < 4.15.7 - Admin+ Stored XSS
The GDPR Cookie Compliance WordPress plugin before 4.15.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1619?
CVE-2025-1619 is classified as a medium-severity vulnerability due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2025-1619?
To fix CVE-2025-1619, update the GDPR Cookie Compliance plugin to version 4.15.7 or later.
Who is affected by CVE-2025-1619?
CVE-2025-1619 affects users of the GDPR Cookie Compliance WordPress plugin prior to version 4.15.7.
What type of vulnerability is CVE-2025-1619?
CVE-2025-1619 is a Stored Cross-Site Scripting vulnerability that can be exploited by high-privilege users.
Can CVE-2025-1619 be exploited by non-admin users?
CVE-2025-1619 primarily allows exploitation by high privilege users, such as administrators.