DIRAS TAKE
Treat this as high priority if your site exposes the plugin to public comments: the flaw allows unauthenticated injection of scripts and there is no vendor-fixed release listed. Immediately restrict comment submission and harden exposure while awaiting a vendor patch.
What is CVE-2026-77263?
An unauthenticated attacker can inject and store malicious JavaScript in pages served by the iubenda All-in-one Compliance for GDPR / CCPA Cookie Consent + more WordPress plugin, allowing that script to run in visitors' browsers. CVE-2026-77263 affects versions 3.13.4 and earlier (3.x branch). The issue is reachable via submitted comment content on sites using the plugin; an attacker only needs the ability to post a comment, no login or special privileges are required. The weakness is classified as CWE-79 (Cross-site Scripting).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Which versions of iubenda iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 3.x | 3.13.4 and earlier |
Is CVE-2026-77263 being exploited?
There are no public reports of exploitation as of 2026-09-30.
How to fix CVE-2026-77263
- Disable or deactivate the iubenda plugin until a vendor fix is released.
- Restrict or moderate public comment submissions and remove untrusted HTML from existing comments.
- Deploy or tighten a Web Application Firewall rule to block suspicious payloads targeting comment fields.
- Monitor webserver and application logs for unexpected script injections and review recent comments for malicious content.
Frequently asked questions
Is CVE-2026-77263 being actively exploited?
There are no public reports of exploitation as of 2026-09-30.
Which iubenda plugin versions are affected by CVE-2026-77263?
Versions 3.13.4 and earlier in the 3.x branch are affected.
Is there a patch for CVE-2026-77263?
No fixed version is listed for this vulnerability; follow vendor guidance and apply mitigations until a patch is released.
Does CVE-2026-77263 require authentication?
No, the vulnerability can be exploited by unauthenticated attackers who can submit comment content to a site running the iubenda plugin.
References
- nvd.nist.gov/vuln/detail/CVE-2026-77263
- cve.org/CVERecord?id=CVE-2026-77263
- wordfence.com/threat-intel/vulnerabilities/id/f8d18aaa-c8f4-4688-841d-2a77b71b60b0?source=cve
- plugins.trac.wordpress.org/browser/iubenda-cookie-law-solution/trunk/iubenda-cookie-class/iubenda.class.php#L941
- plugins.trac.wordpress.org/browser/iubenda-cookie-law-solution/trunk/iubenda-cookie-class/iubenda.class.php#L381
- plugins.trac.wordpress.org/browser/iubenda-cookie-law-solution/trunk/iubenda_cookie_solution.php#L857
- plugins.trac.wordpress.org/browser/iubenda-cookie-law-solution/trunk/iubenda_cookie_solution.php#L834
- plugins.trac.wordpress.org/changeset?reponame=&new=3675630%40iubenda-cookie-law-solution%2Ftags%2F3.13.5&old=3663183%40iubenda-cookie-law-solution%2Ftags%2F3.13.4
- plugins.trac.wordpress.org/changeset/3675630/iubenda-cookie-law-solution/trunk/iubenda-cookie-class/iubenda.class.php
- plugins.trac.wordpress.org/changeset?old_path=%2Fiubenda-cookie-law-solution/tags/3.13.4&new_path=%2Fiubenda-cookie-law-solution/tags/3.13.5
- All iubenda CVEs on CVE Radar
- CVEs published in September 2026