CVE-2025-1621
CVSS 3.1 Score 4.8 of 10 (medium)
Details
Summary
CVE-2025-1621 is a vulnerability affecting the GDPR Cookie Compliance plugin for WordPress. Before version 4.15.7, this plugin fails to properly sanitize and escape certain settings, making it susceptible to Stored Cross-Site Scripting attacks. High privilege users, including admins, can exploit this issue, even when the unfiltered_html capability is disabled in multisite setups. The vulnerability could result in unauthorized script injection and potential data breaches. It is recommended that users update their plugin to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.