CVE-2026-73359: WordPress WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin <= 4.3.9 - Cross Site Scripting (XSS) vulnerability
Subscriber Cross Site Scripting (XSS) in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.3.9 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WP Cookie Notice for GDPR, CCPA & ePrivacy Consentto a version that resolves this vulnerability.Fixed in 4.4.0
Event History
Frequently Asked Questions
Which versions are affected?
The vulnerable versions are 4.3.9 and earlier. The issue is categorized as XSS and is rated medium severity with a CVSS score of 6.5.
What level of access does an attacker need?
An attacker needs Subscriber-level privileges and user interaction to exploit the issue. The CVSS vector indicates network-accessible attack conditions with low attack complexity.
What is the potential impact of exploitation?
Successful exploitation can affect confidentiality, integrity, and availability at low impact, and the scope is changed. This means the XSS may affect resources beyond the initially vulnerable security authority.