DIRAS TAKE
Urgent: no vendor patch is available and the issue allows persistent XSS in visitors’ browsers; immediately disable the affected cookie/script blocker options and enforce strict comment moderation until an update is published.
What is CVE-2026-83561?
Malicious actors can cause persistent JavaScript to be saved and later executed on sites using the Complianz GDPR/CCPA Cookie Consent Banner WordPress plugin, tracked as CVE-2026-83561. The vulnerability affects the 7.x line (including 7.5.4 and earlier). An attacker can post a crafted comment without logging in, but successful exploitation depends on the site running the Elementor plugin, Complianz being configured to block Twitter or Facebook scripts, and an administrator approving the attacker’s comment so the payload becomes persistent and runs when users load the affected page. The weakness is classified as CWE-79 (Cross-site Scripting).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Which versions of complianz Complianz GDPR/CCPA Cookie Consent Banner are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 7.x | 7.5.4 and earlier |
Is CVE-2026-83561 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-83561
- Disable Complianz’s Twitter and Facebook cookie/script blocker settings until a vendor fix is released.
- Require administrator approval for all comments and remove any suspicious stored comments immediately.
- Restrict access to the WordPress admin area and deactivate Elementor if it is not essential for the site.
- Watch Complianz advisories and install the official update as soon as one is released.
Frequently asked questions
Is CVE-2026-83561 being actively exploited?
There are no public reports of exploitation of CVE-2026-83561 as of 2026-09-29.
Which Complianz GDPR/CCPA Cookie Consent Banner versions are affected by CVE-2026-83561?
The vulnerability affects the 7.x branch of the Complianz plugin, specifically versions 7.5.4 and earlier.
Is there a patch for CVE-2026-83561?
No patch is available for CVE-2026-83561 according to the supplied facts; apply mitigations and monitor the vendor for updates.
Does CVE-2026-83561 require authentication?
An attacker can submit the malicious comment without authenticating, but exploitation requires an administrator to approve the comment and the site to have Elementor plus the Complianz Twitter or Facebook blocker enabled.
References
- nvd.nist.gov/vuln/detail/CVE-2026-83561
- cve.org/CVERecord?id=CVE-2026-83561
- wordfence.com/threat-intel/vulnerabilities/id/c53da813-0376-4c61-bfe0-fd8a2c946937?source=cve
- plugins.trac.wordpress.org/browser/complianz-gdpr/tags/7.5.3.1/integrations/plugins/elementor.php#L213
- plugins.trac.wordpress.org/browser/complianz-gdpr/tags/7.5.3.1/integrations/plugins/elementor.php#L206
- plugins.trac.wordpress.org/browser/complianz-gdpr/tags/7.5.3.1/integrations/plugins/elementor.php#L188
- plugins.trac.wordpress.org/browser/complianz-gdpr/tags/7.5.3.1/class-cookie-blocker.php#L828
- plugins.trac.wordpress.org/browser/complianz-gdpr/tags/7.5.3.1/class-cookie-blocker.php#L458
- plugins.trac.wordpress.org/browser/complianz-gdpr/tags/7.5.3.1/functions.php#L1232
- plugins.trac.wordpress.org/changeset?reponame=&new=3686656%40complianz-gdpr%2Ftags%2F7.5.5&old=3674116%40complianz-gdpr%2Ftags%2F7.5.4
- plugins.trac.wordpress.org/changeset/3686618/complianz-gdpr/trunk/integrations/plugins/elementor.php
- plugins.trac.wordpress.org/changeset?reponame=&new=3686656%40complianz-gdpr%2Ftrunk&old=3674116%40complianz-gdpr%2Ftrunk
- All complianz CVEs on CVE Radar
- CVEs published in September 2026