DIRAS TAKE
Urgent: treat as high priority because exploitation requires no authentication and allows persistent script injection when the Secondary parser is enabled. If you expose the plugin on the public web and use the Secondary parser, mitigate immediately.
What is CVE-2026-77233?
Unauthenticated attackers can inject persistent JavaScript into pages served by the iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more WordPress plugin, enabling script execution in visitors' browsers (CVE-2026-77233). The flaw affects versions 3.13.4 and earlier and arises from insufficient input sanitization and output escaping in the AdSense regex rewrite handling. The issue only occurs when the plugin is running its Secondary parser engine (parser_engine=default); an attacker needs only network access and the plugin configured with that parser to exploit it. The weakness is classified as CWE-79 (Cross-site Scripting).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Which versions of iubenda iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 3.x | 3.13.4 and earlier |
Is CVE-2026-77233 being exploited?
There are no public reports of exploitation as of 2026-09-30.
How to fix CVE-2026-77233
- Disable or switch off the Secondary parser engine (set parser_engine to the default 'new' DOM-based parser) until a vendor fix is available.
- Restrict public exposure of sites running the plugin where possible and apply web application firewall rules to block malicious input patterns.
- Monitor webserver and application logs for unexpected comment content or attempts to inject scripts and review site pages for unauthorized script insertion.
- Follow the vendor's guidance and apply official updates when a patch is released.
Frequently asked questions
Is CVE-2026-77233 being actively exploited?
There are no public reports of active exploitation of CVE-2026-77233 as of 2026-09-30.
Which iubenda plugin versions are affected by CVE-2026-77233?
The iubenda | All-in-one Compliance plugin versions 3.13.4 and earlier are affected.
Is there a patch for CVE-2026-77233?
No patch is listed in the provided facts; the affected data shows no fixed version available.
Does CVE-2026-77233 require authentication?
No, exploitation does not require authentication when the Secondary parser engine (parser_engine=default) is enabled.
References
- nvd.nist.gov/vuln/detail/CVE-2026-77233
- cve.org/CVERecord?id=CVE-2026-77233
- wordfence.com/threat-intel/vulnerabilities/id/af459f28-a058-42d3-8818-43603c6a14eb?source=cve
- plugins.trac.wordpress.org/browser/iubenda-cookie-law-solution/tags/3.13.3/iubenda-cookie-class/iubenda.class.php#L570
- plugins.trac.wordpress.org/browser/iubenda-cookie-law-solution/tags/3.13.3/iubenda-cookie-class/iubenda.class.php#L557
- plugins.trac.wordpress.org/browser/iubenda-cookie-law-solution/tags/3.13.3/iubenda_cookie_solution.php#L986
- plugins.trac.wordpress.org/browser/iubenda-cookie-law-solution/tags/3.13.2/iubenda-cookie-class/iubenda.class.php#L570
- plugins.trac.wordpress.org/browser/iubenda-cookie-law-solution/tags/3.13.2/iubenda-cookie-class/iubenda.class.php#L557
- plugins.trac.wordpress.org/browser/iubenda-cookie-law-solution/tags/3.13.2/iubenda_cookie_solution.php#L986
- plugins.trac.wordpress.org/changeset?reponame=&new=3675630%40iubenda-cookie-law-solution%2Ftags%2F3.13.5&old=3663183%40iubenda-cookie-law-solution%2Ftags%2F3.13.4
- plugins.trac.wordpress.org/changeset/3675630/iubenda-cookie-law-solution/trunk/iubenda-cookie-class/iubenda.class.php
- plugins.trac.wordpress.org/changeset?old_path=%2Fiubenda-cookie-law-solution/tags/3.13.4&new_path=%2Fiubenda-cookie-law-solution/tags/3.13.5
- All iubenda CVEs on CVE Radar
- CVEs published in September 2026