CVE-2025-2205

CVSS 3.1 Score 4.4 of 10 (medium)

Details

Published Mar 12, 2025
CWE ID 79

Summary

CVE-2025-2205 is a Stored Cross-Site Scripting (XSS) vulnerability affecting the GDPR Cookie Compliance plugin for WordPress. This issue, present in versions up to 4.15.6, allows authenticated attackers with administrator-level permissions to inject malicious scripts into admin settings. The vulnerability arises due to insufficient input sanitization and output escaping, enabling attackers to execute arbitrary web scripts. This issue only impacts multi-site installations and setups where unfiltered_html has been disabled. Users are advised to update the plugin to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share