CVE-2026-73359
Received Received - Intake

Subscriber XSS in WP Cookie Notice for GDPR <= 4.3.9

Vulnerability report for CVE-2026-73359, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-18

Last updated on: 2026-08-18

Assigner: Patchstack

Description

Subscriber Cross Site Scripting (XSS) in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.3.9 versions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-18
Last Modified
2026-08-18
Generated
2026-08-18
AI Q&A
2026-08-18
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
wp_cookie_notice gdpr_ccpa_eprivacy_consent to 4.3.9 (inc)
wp_cookie_notice wp_cookie_notice to 4.3.9 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Subscriber Cross Site Scripting (XSS) vulnerability in the WordPress plugin WP Cookie Notice for GDPR, CCPA & ePrivacy Consent affecting versions 4.3.9 and below. Attackers can inject malicious scripts into websites that execute when visitors access the site.

Detection Guidance

To detect this XSS vulnerability in the WP Cookie Notice plugin, check if your WordPress site is running versions 4.3.9 or below. Inspect the plugin files for suspicious script injections in user input fields or output areas. Monitor web server logs for unusual requests targeting the plugin's endpoints.

Impact Analysis

Attackers can execute malicious scripts on your site when visitors access it. This requires user interaction like clicking a malicious link. Privileged users such as subscribers or developers are typically targeted.

Compliance Impact

This vulnerability could compromise user data protection measures required by GDPR and similar regulations. A successful XSS attack may lead to unauthorized data access or manipulation, potentially violating compliance.

Mitigation Strategies

Immediately update the WP Cookie Notice plugin to version 4.4.0 or later. If updating is not possible, use a web application firewall or security plugin like Patchstack to block malicious requests until the update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-73359. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart