CVE-2025-1621

CVSS 3.1 Score 4.8 of 10 (medium)

Details

Published Mar 16, 2025
Updated: Apr 2, 2025
CWE ID 79

Summary

CVE-2025-1621 is a vulnerability affecting the GDPR Cookie Compliance plugin for WordPress. Before version 4.15.7, this plugin fails to properly sanitize and escape certain settings, making it susceptible to Stored Cross-Site Scripting attacks. High privilege users, including admins, can exploit this issue, even when the unfiltered_html capability is disabled in multisite setups. The vulnerability could result in unauthorized script injection and potential data breaches. It is recommended that users update their plugin to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share