CVE-2026-83561: stored cross-site scripting in complianz Complianz GDPR/CCPA Cookie Consent Banner

Malicious actors can cause persistent JavaScript to be saved and later executed on sites using the Complianz GDPR/CCPA Cookie Consent Banner WordPress plugin, tracked as CVE-2026-83561. The vulnerability affects the 7.x line (including 7.5.4 and earlier). An attacker can post a crafted comment without logging in, but successful exploitation depends on the site running the Elementor plugin, Complianz being configured to block Twitter or Facebook scripts, and an administrator approving the attacker’s comment so the payload becomes persistent and runs when users load the affected page.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
7.2HIGH
EPSS
0.00508
CWE
CWE-79
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: no vendor patch is available and the issue allows persistent XSS in visitors’ browsers; immediately disable the affected cookie/script blocker options and enforce strict comment moderation until an update is published.

What is CVE-2026-83561?

Malicious actors can cause persistent JavaScript to be saved and later executed on sites using the Complianz GDPR/CCPA Cookie Consent Banner WordPress plugin, tracked as CVE-2026-83561. The vulnerability affects the 7.x line (including 7.5.4 and earlier). An attacker can post a crafted comment without logging in, but successful exploitation depends on the site running the Elementor plugin, Complianz being configured to block Twitter or Facebook scripts, and an administrator approving the attacker’s comment so the payload becomes persistent and runs when users load the affected page. The weakness is classified as CWE-79 (Cross-site Scripting).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

Which versions of complianz Complianz GDPR/CCPA Cookie Consent Banner are affected?

BRANCHAFFECTEDFIXED
7.x7.5.4 and earlier

Is CVE-2026-83561 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-83561

  1. Disable Complianz’s Twitter and Facebook cookie/script blocker settings until a vendor fix is released.
  2. Require administrator approval for all comments and remove any suspicious stored comments immediately.
  3. Restrict access to the WordPress admin area and deactivate Elementor if it is not essential for the site.
  4. Watch Complianz advisories and install the official update as soon as one is released.

Frequently asked questions

Is CVE-2026-83561 being actively exploited?

There are no public reports of exploitation of CVE-2026-83561 as of 2026-09-29.

Which Complianz GDPR/CCPA Cookie Consent Banner versions are affected by CVE-2026-83561?

The vulnerability affects the 7.x branch of the Complianz plugin, specifically versions 7.5.4 and earlier.

Is there a patch for CVE-2026-83561?

No patch is available for CVE-2026-83561 according to the supplied facts; apply mitigations and monitor the vendor for updates.

Does CVE-2026-83561 require authentication?

An attacker can submit the malicious comment without authenticating, but exploitation requires an administrator to approve the comment and the site to have Elementor plus the Complianz Twitter or Facebook blocker enabled.

References