CVE-2026-77263: stored cross-site scripting in iubenda iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more

An unauthenticated attacker can inject and store malicious JavaScript in pages served by the iubenda All-in-one Compliance for GDPR / CCPA Cookie Consent + more WordPress plugin, allowing that script to run in visitors' browsers. CVE-2026-77263 affects versions 3.13.4 and earlier (3.x branch). The issue is reachable via submitted comment content on sites using the plugin; an attacker only needs the ability to post a comment, no login or special privileges are required.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
7.2HIGH
EPSS
0.00428
CWE
CWE-79
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Treat this as high priority if your site exposes the plugin to public comments: the flaw allows unauthenticated injection of scripts and there is no vendor-fixed release listed. Immediately restrict comment submission and harden exposure while awaiting a vendor patch.

What is CVE-2026-77263?

An unauthenticated attacker can inject and store malicious JavaScript in pages served by the iubenda All-in-one Compliance for GDPR / CCPA Cookie Consent + more WordPress plugin, allowing that script to run in visitors' browsers. CVE-2026-77263 affects versions 3.13.4 and earlier (3.x branch). The issue is reachable via submitted comment content on sites using the plugin; an attacker only needs the ability to post a comment, no login or special privileges are required. The weakness is classified as CWE-79 (Cross-site Scripting).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

Which versions of iubenda iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more are affected?

BRANCHAFFECTEDFIXED
3.x3.13.4 and earlier

Is CVE-2026-77263 being exploited?

There are no public reports of exploitation as of 2026-09-30.

How to fix CVE-2026-77263

  1. Disable or deactivate the iubenda plugin until a vendor fix is released.
  2. Restrict or moderate public comment submissions and remove untrusted HTML from existing comments.
  3. Deploy or tighten a Web Application Firewall rule to block suspicious payloads targeting comment fields.
  4. Monitor webserver and application logs for unexpected script injections and review recent comments for malicious content.

Frequently asked questions

Is CVE-2026-77263 being actively exploited?

There are no public reports of exploitation as of 2026-09-30.

Which iubenda plugin versions are affected by CVE-2026-77263?

Versions 3.13.4 and earlier in the 3.x branch are affected.

Is there a patch for CVE-2026-77263?

No fixed version is listed for this vulnerability; follow vendor guidance and apply mitigations until a patch is released.

Does CVE-2026-77263 require authentication?

No, the vulnerability can be exploited by unauthenticated attackers who can submit comment content to a site running the iubenda plugin.

References