CVE-2026-2389: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-2389 is a Stored Cross-Site Scripting (XSS) vulnerability in the Complianz – GDPR/CCPA Cookie Consent plugin for WordPress, affecting all versions up to and including 7.4.4.2. The flaw exists in the revert_divs_to_summary function, which replaces ” HTML entities with literal double-quote characters in post content without subsequent sanitization, enabling injection of arbitrary web scripts. Exploitation requires Contributor-level authentication and the Classic Editor plugin to be installed and active. It was published on March 26, 2026, with a CVSS v3.1 base score of 4.9 (Medium) (Wordfence, EUVD).

Technical details

The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation – Cross-Site Scripting). The revert_divs_to_summary function in class-document.php performs an unsanitized replacement of the ” HTML entity with a literal double-quote character (") in post content, allowing an attacker to break out of HTML attribute contexts and inject malicious script tags or event handlers. Exploitation requires the attacker to hold at least Contributor-level access on the WordPress site and for the Classic Editor plugin to be installed and activated, as the vulnerability is triggered through the Classic Editor's post-saving workflow. The vulnerable code path is visible in the plugin's source at version 7.4.4.2 and was patched in the subsequent changeset (Wordfence, WordPress Trac).

Impact

Successful exploitation allows an authenticated attacker with Contributor-level access to persistently inject arbitrary JavaScript into WordPress pages, which executes in the browsers of any user who visits the affected page. This can lead to session cookie theft, credential harvesting, defacement, or redirection of site visitors to malicious content. The scope is changed (S:C in CVSS terms), meaning the injected script can affect users beyond the attacker's own session, though confidentiality and integrity impacts are rated low and there is no direct availability impact (Wordfence, EUVD).

Exploitability

No public exploit code or evidence of in-the-wild exploitation has been reported for CVE-2026-2389 as of the available data. The EPSS score is approximately 0.03%, indicating a very low probability of exploitation in the near term. Exploitation requires authenticated access at the Contributor level or above, as well as the Classic Editor plugin being active, which meaningfully limits the attack surface. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Wordfence).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Complianz – GDPR/CCPA Cookie Consent plugin at version 7.4.4.2 or earlier, with the Classic Editor plugin also installed and active.
  2. Obtain Contributor access: Register or compromise an account with at least Contributor-level privileges on the target WordPress site.
  3. Craft malicious post content: Create or edit a post using the Classic Editor, embedding a payload that exploits the unsanitized &#8221; entity replacement — for example, inserting content that, after the revert_divs_to_summary function processes it, results in a <script> tag or an injected onerror/onload attribute containing arbitrary JavaScript.
  4. Save and publish: Submit the post so that the plugin's revert_divs_to_summary function processes the content, converting the HTML entity to a literal double-quote and leaving the injected script unsanitized in the stored post content.
  5. Trigger execution: When any user (including administrators) visits the page containing the injected content, the malicious script executes in their browser, enabling session hijacking, credential theft, or further attacks (Wordfence, WordPress Trac).

Indicators of compromise

  • Logs: WordPress access logs showing POST requests to wp-admin/post.php or REST API post endpoints from Contributor-level accounts, particularly with unusual encoded content in the request body.
  • File System: Unexpected JavaScript content (e.g., <script> tags, onerror=, onload= attributes) stored in WordPress post content within the database, associated with posts edited via the Classic Editor while the Complianz plugin is active.
  • Network: Outbound connections from victim browsers to unknown external domains following page visits, which may indicate active XSS payload execution (e.g., cookie exfiltration endpoints).
  • Database: WordPress wp_posts table entries containing raw double-quote characters in contexts that should be HTML-encoded, or containing inline script content in posts authored by Contributor-level users.

Mitigation and workarounds

WordPress site administrators should update the Complianz – GDPR/CCPA Cookie Consent plugin to a version beyond 7.4.4.2, where the sanitization issue in revert_divs_to_summary has been addressed (see the patch changeset). As a temporary workaround, deactivating the Classic Editor plugin will prevent exploitation of this specific vulnerability, since the attack path requires it to be active. Additionally, restricting Contributor-level user registration and auditing existing Contributor accounts can reduce exposure until the patch is applied (Wordfence, WordPress Trac Changeset).

Community reactions

Wordfence disclosed the vulnerability through its threat intelligence platform and included it in its weekly WordPress vulnerability report for the period of March 23–29, 2026. Sucuri also referenced the vulnerability in its March 2026 vulnerability patch roundup. No significant broader media coverage or notable researcher commentary beyond these standard disclosure channels has been identified (Wordfence Blog, Sucuri Blog).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management