
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2389 is a Stored Cross-Site Scripting (XSS) vulnerability in the Complianz – GDPR/CCPA Cookie Consent plugin for WordPress, affecting all versions up to and including 7.4.4.2. The flaw exists in the revert_divs_to_summary function, which replaces ” HTML entities with literal double-quote characters in post content without subsequent sanitization, enabling injection of arbitrary web scripts. Exploitation requires Contributor-level authentication and the Classic Editor plugin to be installed and active. It was published on March 26, 2026, with a CVSS v3.1 base score of 4.9 (Medium) (Wordfence, EUVD).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation – Cross-Site Scripting). The revert_divs_to_summary function in class-document.php performs an unsanitized replacement of the ” HTML entity with a literal double-quote character (") in post content, allowing an attacker to break out of HTML attribute contexts and inject malicious script tags or event handlers. Exploitation requires the attacker to hold at least Contributor-level access on the WordPress site and for the Classic Editor plugin to be installed and activated, as the vulnerability is triggered through the Classic Editor's post-saving workflow. The vulnerable code path is visible in the plugin's source at version 7.4.4.2 and was patched in the subsequent changeset (Wordfence, WordPress Trac).
Successful exploitation allows an authenticated attacker with Contributor-level access to persistently inject arbitrary JavaScript into WordPress pages, which executes in the browsers of any user who visits the affected page. This can lead to session cookie theft, credential harvesting, defacement, or redirection of site visitors to malicious content. The scope is changed (S:C in CVSS terms), meaning the injected script can affect users beyond the attacker's own session, though confidentiality and integrity impacts are rated low and there is no direct availability impact (Wordfence, EUVD).
No public exploit code or evidence of in-the-wild exploitation has been reported for CVE-2026-2389 as of the available data. The EPSS score is approximately 0.03%, indicating a very low probability of exploitation in the near term. Exploitation requires authenticated access at the Contributor level or above, as well as the Classic Editor plugin being active, which meaningfully limits the attack surface. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Wordfence).
” entity replacement — for example, inserting content that, after the revert_divs_to_summary function processes it, results in a <script> tag or an injected onerror/onload attribute containing arbitrary JavaScript.revert_divs_to_summary function processes the content, converting the HTML entity to a literal double-quote and leaving the injected script unsanitized in the stored post content.wp-admin/post.php or REST API post endpoints from Contributor-level accounts, particularly with unusual encoded content in the request body.<script> tags, onerror=, onload= attributes) stored in WordPress post content within the database, associated with posts edited via the Classic Editor while the Complianz plugin is active.wp_posts table entries containing raw double-quote characters in contexts that should be HTML-encoded, or containing inline script content in posts authored by Contributor-level users.WordPress site administrators should update the Complianz – GDPR/CCPA Cookie Consent plugin to a version beyond 7.4.4.2, where the sanitization issue in revert_divs_to_summary has been addressed (see the patch changeset). As a temporary workaround, deactivating the Classic Editor plugin will prevent exploitation of this specific vulnerability, since the attack path requires it to be active. Additionally, restricting Contributor-level user registration and auditing existing Contributor accounts can reduce exposure until the patch is applied (Wordfence, WordPress Trac Changeset).
Wordfence disclosed the vulnerability through its threat intelligence platform and included it in its weekly WordPress vulnerability report for the period of March 23–29, 2026. Sucuri also referenced the vulnerability in its March 2026 vulnerability patch roundup. No significant broader media coverage or notable researcher commentary beyond these standard disclosure channels has been identified (Wordfence Blog, Sucuri Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."