Skip to main content
Vulnerability Database/CVE-2026-83561

CVE-2026-83561: WordPress Complianz Plugin XSS Vulnerability

CVE-2026-83561 is a stored XSS vulnerability in the Complianz GDPR/CCPA Cookie Consent plugin for WordPress that allows attackers to inject malicious scripts. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-83561 Overview

The Complianz GDPR/CCPA Cookie Consent Banner plugin for WordPress contains a stored Cross-Site Scripting (XSS) vulnerability affecting all versions up to and including 7.5.4. The flaw resides in the Elementor Cookie Blocker Regex handling and stems from insufficient input sanitization and output escaping of comment content [CWE-79]. Unauthenticated attackers can inject arbitrary JavaScript that executes in the browser of any user visiting an affected page. Exploitation requires an administrator to approve the attacker's comment, and the site must have the Elementor plugin installed with Complianz configured to block Twitter or Facebook cookies/scripts.

Critical Impact

Attackers can achieve persistent script execution against site visitors, enabling session theft, forced administrative actions, and drive-by redirection through malicious comment payloads.

Affected Products

  • Complianz GDPR/CCPA Cookie Consent Banner plugin for WordPress, all versions through 7.5.4
  • WordPress sites running Elementor alongside the vulnerable Complianz version
  • Complianz configurations with the Twitter or Facebook cookie/script blocker enabled

Discovery Timeline

  • 2026-09-18 - CVE-2026-83561 published to NVD
  • 2026-09-18 - Last updated in NVD database

Technical Details for CVE-2026-83561

Vulnerability Analysis

CVE-2026-83561 is a stored Cross-Site Scripting (XSS) issue introduced through the plugin's Elementor integration. The Complianz Cookie Blocker rewrites page content by matching third-party script patterns using regular expressions. When the Twitter or Facebook blocker is enabled, comment content that flows through the Elementor rendering path is processed by the blocker's regex-based transformation without sufficient sanitization or output escaping. Attacker-supplied markup embedded in a comment survives this pipeline and is emitted directly into the rendered HTML.

Although exploitation requires administrator approval of the malicious comment, the attacker does not need any authentication to submit it. Once approved, the payload is stored server-side and executes in every visitor's browser session that renders the affected page.

Root Cause

The root cause is missing input validation and output encoding within the Elementor integration paths of the Complianz plugin, specifically around the cookie/script blocker regex processing in class-cookie-blocker.php and integrations/plugins/elementor.php. Comment content is passed through cookie-blocking transformations that do not neutralize HTML or JavaScript syntax before returning it to the DOM. See the WordPress Cookie Blocker Code and Elementor Integration Code for the affected functions.

Attack Vector

The attack is delivered over the network with no privileges required. An unauthenticated attacker submits a WordPress comment containing crafted markup or script content targeting the Twitter or Facebook blocker regex. After an administrator approves the comment, the payload is stored and executed for every subsequent visitor. See the Wordfence Vulnerability Report for additional context.

Detection Methods for CVE-2026-83561

Indicators of Compromise

  • Approved comments containing <script> tags, onerror/onload handlers, or references to Twitter/Facebook script domains not present in expected content
  • Unexpected outbound requests from visitor browsers to attacker-controlled domains sourced from post or comment pages
  • Presence of the Complianz plugin at version 7.5.4 or earlier alongside an active Elementor installation and enabled Twitter or Facebook blocker

Detection Strategies

  • Audit stored WordPress comments for HTML event handlers, encoded script fragments, and suspicious URL patterns that could survive regex rewriting
  • Compare rendered post HTML against server-stored comment content to identify unauthorized script injection in the output pipeline
  • Review Complianz configuration for enabled Twitter and Facebook blockers in combination with vulnerable plugin versions

Monitoring Recommendations

  • Enable web server request logging for comment submission endpoints and alert on payloads containing script-like tokens
  • Monitor administrator moderation actions and correlate approved comments with subsequent visitor-side JavaScript errors or redirects
  • Track outbound Content Security Policy (CSP) violation reports from visitor browsers to identify injected scripts

How to Mitigate CVE-2026-83561

Immediate Actions Required

  • Upgrade the Complianz GDPR/CCPA Cookie Consent Banner plugin to version 7.5.5 or later
  • Review the pending and approved comment queue for suspicious HTML or script content prior to upgrading
  • Restrict administrator comment moderation to trained personnel and require review of raw HTML content before approval

Patch Information

The vendor addressed the vulnerability in Complianz version 7.5.5. Fixes are documented in WordPress Changeset 3686618 and WordPress Changeset 3686656, which introduce sanitization and escaping across the Elementor integration paths.

Workarounds

  • Disable the Twitter and Facebook cookie/script blockers in Complianz until the plugin is upgraded
  • Disable public comment submission or require authenticated commenting to reduce unauthenticated attacker reach
  • Deploy a Content Security Policy (CSP) that restricts inline scripts and limits allowed script sources to trusted origins
bash
# Configuration example: update the Complianz plugin via WP-CLI
wp plugin update complianz-gdpr --version=7.5.5
wp plugin list --name=complianz-gdpr --fields=name,version,status

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.