CVE-2026-77233: stored cross-site scripting in iubenda iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more

Unauthenticated attackers can inject persistent JavaScript into pages served by the iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more WordPress plugin, enabling script execution in visitors' browsers (CVE-2026-77233). The flaw affects versions 3.13.4 and earlier and arises from insufficient input sanitization and output escaping in the AdSense regex rewrite handling. The issue only occurs when the plugin is running its Secondary parser engine (parser_engine=default); an attacker needs only network access and the plugin configured with that parser to exploit it.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
7.2HIGH
EPSS
0.00508
CWE
CWE-79
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: treat as high priority because exploitation requires no authentication and allows persistent script injection when the Secondary parser is enabled. If you expose the plugin on the public web and use the Secondary parser, mitigate immediately.

What is CVE-2026-77233?

Unauthenticated attackers can inject persistent JavaScript into pages served by the iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more WordPress plugin, enabling script execution in visitors' browsers (CVE-2026-77233). The flaw affects versions 3.13.4 and earlier and arises from insufficient input sanitization and output escaping in the AdSense regex rewrite handling. The issue only occurs when the plugin is running its Secondary parser engine (parser_engine=default); an attacker needs only network access and the plugin configured with that parser to exploit it. The weakness is classified as CWE-79 (Cross-site Scripting).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

Which versions of iubenda iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more are affected?

BRANCHAFFECTEDFIXED
3.x3.13.4 and earlier

Is CVE-2026-77233 being exploited?

There are no public reports of exploitation as of 2026-09-30.

How to fix CVE-2026-77233

  1. Disable or switch off the Secondary parser engine (set parser_engine to the default 'new' DOM-based parser) until a vendor fix is available.
  2. Restrict public exposure of sites running the plugin where possible and apply web application firewall rules to block malicious input patterns.
  3. Monitor webserver and application logs for unexpected comment content or attempts to inject scripts and review site pages for unauthorized script insertion.
  4. Follow the vendor's guidance and apply official updates when a patch is released.

Frequently asked questions

Is CVE-2026-77233 being actively exploited?

There are no public reports of active exploitation of CVE-2026-77233 as of 2026-09-30.

Which iubenda plugin versions are affected by CVE-2026-77233?

The iubenda | All-in-one Compliance plugin versions 3.13.4 and earlier are affected.

Is there a patch for CVE-2026-77233?

No patch is listed in the provided facts; the affected data shows no fixed version available.

Does CVE-2026-77233 require authentication?

No, exploitation does not require authentication when the Secondary parser engine (parser_engine=default) is enabled.

References