Junglewise Threat Intelligence

CVE-2026-77233: iubenda Compliance Cookie Consent stored cross-site scripting via AdSense regex rewrite

CVE-2026-77233 · Severity: high · CVSS 7.2 · Published 2026-09-05

Executive brief

The iubenda WordPress plugin provides GDPR/CCPA cookie consent management for websites. An unauthenticated attacker can inject malicious JavaScript into page comments that executes for all visitors, compromising site security and potentially stealing visitor data or redirecting users to malicious sites when a specific parser engine is active.

Technical details

The plugin contains a stored cross-site scripting (XSS) vulnerability in comment content handling via the AdSense regex rewrite functionality, caused by insufficient input sanitization and output escaping. The vulnerability affects versions up to 3.13.4 and only manifests when the 'Secondary' parser engine is active (parser_engine=default); the default 'new' DOM-based parser is not affected. Unauthenticated attackers can inject arbitrary web scripts into page comments that persistently execute whenever any user accesses the injected page. A patch is assumed to be available in versions after 3.13.4.

Affected products

  • iubenda All-in-one Compliance for GDPR / CCPA Cookie Consent plugin up to and including 3.13.4

Timeline

  • 2026-09-05: disclosed

References