CVE-2025-1619
CVSS 3.1 Score 4.8 of 10 (medium)
Details
Published Mar 16, 2025
Updated: Apr 2, 2025
CWE ID 79
Summary
CVE-2025-1619 is a vulnerability affecting the GDPR Cookie Compliance plugin for WordPress. The issue lies in the plugin's failure to sanitize and escape certain settings, making it susceptible to Stored Cross-Site Scripting (XSS) attacks. High privilege users, including admins, can exploit this vulnerability, even when the unfiltered_html capability is disabled, as seen in multisite setups. This weakness could lead to unauthorized script injection and potential data breaches. Users are urged to update the plugin to version 4.15.7 to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.