CVE-2026-92977: Real Cookie Banner: GDPR & ePrivacy Cookie Consent <= 5.3.5 - Unauthenticated Stored Cross-Site Scripting via Comment
The Real Cookie Banner: GDPR & ePrivacy Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment in all versions up to, and including, 5.3.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Malicious script payloads placed in the title attribute of an anchor tag survive WordPress's comment kses filter at save time, as the payload is only promoted to executable HTML attributes when the plugin's page-wide regex strips the closing quote delimiter at render time; exploitability is therefore subject to the standard comment moderation workflow before the comment is publicly displayed.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker does not need authentication and can submit a malicious comment containing a crafted anchor tag. The payload executes when someone accesses the page where the injected comment is displayed.
Are sites with comment moderation enabled still exposed?
Exploitability depends on the normal comment moderation workflow. The malicious comment must be publicly displayed before its script payload can execute, so moderation can prevent exploitation if the comment is not approved or published.
What input pattern triggers the vulnerability?
The issue involves a script payload placed in the title attribute of an anchor tag. WordPress's comment KSES filter permits it at save time, and the plugin's page-wide regular expression removes the closing quote delimiter during rendering, promoting the payload into executable HTML attributes.
How can I determine whether my site is affected?
Sites using Real Cookie Banner versions up to and including 5.3.5 are affected according to the available data. Review publicly displayed comments for suspicious anchor tags and unexpected content in title attributes, particularly on pages where comments are rendered.