CyberRota Analysis
AI-GeneratedThe WP Cookie Notice for GDPR, CCPA & ePrivacy Consent versions up to 4.3.9 are vulnerable to a Subscriber Cross Site Scripting (XSS) attack, which could allow an attacker to inject malicious scripts into web pages viewed by users. This vulnerability poses a medium risk, potentially compromising user data and session integrity. Website administrators using the affected plugin should prioritize updating to mitigate the risk of exploitation.
CVE
CVE-2026-73359
Severity
MEDIUM
CVSS
6.5
EPSS
0.21%
Original NVD Description
Subscriber Cross Site Scripting (XSS) in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.3.9 versions.