CVE-2025-1620: GDPR Cookie Compliance < 4.15.7 - Admin+ Stored XSS
The GDPR Cookie Compliance WordPress plugin before 4.15.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1620?
CVE-2025-1620 is considered a high-severity vulnerability due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2025-1620?
To fix CVE-2025-1620, update the GDPR Cookie Compliance WordPress plugin to version 4.15.7 or later.
Who is affected by CVE-2025-1620?
CVE-2025-1620 affects installations of the GDPR Cookie Compliance WordPress plugin prior to version 4.15.7.
What type of attack can CVE-2025-1620 facilitate?
CVE-2025-1620 can facilitate Stored Cross-Site Scripting attacks which may compromise site security.
Can low privilege users exploit CVE-2025-1620?
No, CVE-2025-1620 specifically allows high privilege users, such as admins, to exploit the vulnerability.